Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Phpbb Group Phpbb Advanced Guestbook | 2/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Dbscripts Dbguestbook | 2/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Hyperbook Guestbook | 2/3/2007 | 16/6/2026 | Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat. | |
| Modificada | Media (6.8) | 1.2% | — | Phpbb Group Phpbb Advanced Guestbook | 2/3/2007 | 16/6/2026 | SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Kvguestbook | 14/2/2007 | 16/6/2026 | The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables. | |
| Modificada | Media (6.8) | 1.2% | — | 212cafe Guestbook | 29/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Advanced Guestbook | 26/1/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | MGB Opensource Guestbook | 19/1/2007 | 16/6/2026 | SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5.1) | 2.2% | 💥 Exploit | DT Guestbook | 16/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Alexphpteam Alex Guestbook | 11/1/2007 | 16/6/2026 | Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory,… | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Alexphpteam Alex Guestbook | 11/1/2007 | 16/6/2026 | SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Sven Moderow Guestbook | 5/1/2007 | 16/6/2026 | Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/. | |
| Modificada | Media (6.8) | 1.4% | — | Alexphpteam Alex Guestbook | 4/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in @lex Guestbook 4.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter. | |
| Modificada | Media (5) | 1.5% | — | Alexphpteam Alex Guestbook | 4/12/2006 | 16/6/2026 | index.php in @lex Guestbook 4.0.1 allows remote attackers to obtain sensitive information via a skin parameter referencing a nonexistent skin, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 2.0% | — | Advanced Guestbook | 8/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | |
| Modificada | Media (5) | 1.7% | — | Digioz Guestbook | 7/11/2006 | 16/6/2026 | list.php in DigiOz Guestbook before 1.7.1 allows remote attackers to obtain sensitive information via a non-numeric page parameter, which displays the installation path in the resulting error message. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ascended Development Ascended Guestbook | 26/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Afgb Guestbook | 17/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php. | |
| Modificada | Media (5.1) | 16% | 💥 Exploit | Telekorn Signkorn Guestbook | 19/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4)… | |
| Modificada | Media (5.1) | 7.7% | 💥 Exploit | Telekorn Signkorn Guestbook | 14/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Doika Guestbook | 24/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gbook.php in Doika guestbook 2.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Simple One-file Guestbook | 14/8/2006 | 16/6/2026 | Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Knusperleicht Guestbook | 7/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter. | |
| Modificada | Media (5) | 1.4% | — | Xguestbook | 31/7/2006 | 16/6/2026 | post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.4% | — | Phptoys Micro Guestbook | 25/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields. |