Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Spy Hat

#21061of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2005-2527
7.5
2005-05-14
Unknown · Advanced Guestbook · CVE-2005-1548
**Name of the Vulnerable Software and Affected Versions** Advanced Guestbook version 2.3.1 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `entry` parameter in the index.php file. **Recommendations** For Advanced Guestbook version 2.3.1, update to a version that fixes this issue, as using the `entry` parameter in the index.php file can lead to arbitrary SQL command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2005-2490
4.3
2005-05-11
Megabook · Megabook · CVE-2005-1494
**Name of the Vulnerable Software and Affected Versions** MegaBook versions 2.0 through 2.1 **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The `entryid` and `password` parameters are specifically vulnerable to such injections. **Recommendations** For MegaBook versions 2.0 and 2.1, avoid using the `entryid` and `password` parameters in the admin.cgi until a fix is available. As a temporary workaround, consider restricting access to the admin.cgi to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.