Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Phpbb Group Phpbb Advanced Guestbook2/3/200716/6/2026
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.
ModificadaAlta (7.5)3.2%💥 ExploitDbscripts Dbguestbook2/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.
ModificadaMedia (5)2.6%💥 ExploitHyperbook Guestbook2/3/200716/6/2026
Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.
ModificadaMedia (6.8)1.2%—Phpbb Group Phpbb Advanced Guestbook2/3/200716/6/2026
SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.
ModificadaAlta (7.5)1.4%—Kvguestbook14/2/200716/6/2026
The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.
ModificadaMedia (6.8)1.2%—212cafe Guestbook29/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.
ModificadaAlta (7.5)1.2%—Advanced Guestbook26/1/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third…
ModificadaAlta (7.5)2.1%💥 ExploitMGB Opensource Guestbook19/1/200716/6/2026
SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5.1)2.2%💥 ExploitDT Guestbook16/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter.
ModificadaAlta (7.5)3.3%💥 ExploitAlexphpteam Alex Guestbook11/1/200716/6/2026
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory,…
ModificadaAlta (7.5)3.8%💥 ExploitAlexphpteam Alex Guestbook11/1/200716/6/2026
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.
ModificadaAlta (7.5)1.6%—Sven Moderow Guestbook5/1/200716/6/2026
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.
ModificadaMedia (6.8)1.4%—Alexphpteam Alex Guestbook4/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in @lex Guestbook 4.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.
ModificadaMedia (5)1.5%—Alexphpteam Alex Guestbook4/12/200616/6/2026
index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain sensitive information via a skin parameter referencing a nonexistent skin, which reveals the installation path in an error message.
ModificadaAlta (7.5)2.0%—Advanced Guestbook8/11/200616/6/2026
PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
ModificadaMedia (5)1.7%—Digioz Guestbook7/11/200616/6/2026
list.php in DigiOz Guestbook before 1.7.1 allows remote attackers to obtain sensitive information via a non-numeric page parameter, which displays the installation path in the resulting error message.
ModificadaAlta (7.5)2.8%💥 ExploitAscended Development Ascended Guestbook26/10/200616/6/2026
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.
ModificadaAlta (7.5)9.7%💥 ExploitAfgb Guestbook17/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php.
ModificadaMedia (5.1)16%💥 ExploitTelekorn Signkorn Guestbook19/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4)…
ModificadaMedia (5.1)7.7%💥 ExploitTelekorn Signkorn Guestbook14/9/200616/6/2026
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
ModificadaMedia (6.8)1.6%—Doika Guestbook24/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in gbook.php in Doika guestbook 2.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaAlta (7.5)3.2%💥 ExploitSimple One-file Guestbook14/8/200616/6/2026
Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php.
ModificadaAlta (7.5)2.6%💥 ExploitKnusperleicht Guestbook7/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
ModificadaMedia (5)1.4%—Xguestbook31/7/200616/6/2026
post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.
ModificadaMedia (4.3)1.4%—Phptoys Micro Guestbook25/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields.
Orbitaley — Vulnerabilidades