Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 5.5% | 💥 Exploit | DM Guestbook | 5/11/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lng parameter to (a) guestbook.php, (b) admin/admin.guestbook.php, or (c) auto/glob_new.php; or (2) the lngdefault parameter to… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | DON Barnes Drbguestbook | 5/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | X-script Guestbook | 3/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Comscripts CS Guestbook | 18/9/2007 | 16/6/2026 | CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Stadtaus Guestbook Script | 9/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) entries.php, (6) index.php, (7) logout.php, or (8) settings.php in… | |
| Modificada | Alta (7.5) | 1.1% | — | Qt-cute Quicktalk Guestbook | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in qtg_msg_view.php in QuickTalk guestbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.1) | 1.8% | — | Advanced Guestbook | 9/5/2007 | 16/6/2026 | Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Advanced Guestbook | 9/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter. | |
| Modificada | Media (5.1) | 7.5% | 💥 Exploit | Advanced Guestbook | 9/5/2007 | 16/6/2026 | Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | BIG Blue Guestbook | 24/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form. | |
| Modificada | Alta (10) | 2.2% | — | FAC Guestbook | 18/4/2007 | 16/6/2026 | FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb. | |
| Modificada | Alta (10) | 2.1% | — | FAC Guestbook | 18/4/2007 | 16/6/2026 | FAC Guestbook 3.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/gbdb.mdb. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Limesoft Guestbook | 18/4/2007 | 16/6/2026 | Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Limesoft Guestbook | 18/4/2007 | 16/6/2026 | Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Dreamcodes Pcp-guestbook | 10/4/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php. | |
| Modificada | Media (4.3) | 0.84% | — | Realguestbook | 23/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to… | |
| Modificada | Alta (7.5) | 1.1% | — | Realguestbook | 23/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in realGuestbook 5.01 allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, and (4) text parameters to save_entry.php, as reachable through add_entry.php; and possibly other unspecified parameters and files. NOTE: the provenance of… | |
| Modificada | Media (4.3) | 1.1% | — | Realguestbook | 23/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in save_entry.php in realGuestbook 5.01 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter, as reachable through add_entry.php. NOTE: the original report stated that the vulnerability was in add_entry.php, which does not receive the input… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Creative Guestbook | 16/3/2007 | 16/6/2026 | Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Creative Guestbook | 16/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. | |
| Modificada | Alta (10) | 2.9% | — | Carbonize Lazarus Guestbook | 16/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Postguestbook | 10/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Li-scripts Li-guestbook | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected. | |
| Modificada | Media (6.8) | 1.4% | — | Savas Place Savas Guestbook | 7/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters. | |
| Modificada | Media (6.8) | 1.2% | — | Savas Place Savas Guestbook | 7/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters. |