Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.2% | — | Professional Home Page Tools Guestbook | 25/7/2006 | 16/6/2026 | delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout. | |
| Modificada | Media (6.4) | 1.2% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash. | |
| Modificada | Alta (7.5) | 1.5% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Pixelated BY LEV Guestbook | 18/7/2006 | 16/6/2026 | SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Carbonize Lazarus Guestbook | 18/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file. | |
| Modificada | Media (5.8) | 1.3% | — | Pixelated BY LEV Guestbook | 18/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message (aka comments), (3) website, and (4) email parameters, which bypasses XSS protection mechanisms that check for… | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Fantastic Guestbook Project Fantastic Guestbook | 13/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters. | |
| Modificada | Media (5.8) | 1.3% | — | Sport-slo Advanced Guestbook | 12/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Sport-slo Advanced Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) name and (2) form parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | George Currums Open Guestbook | 29/6/2006 | 16/6/2026 | SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Georgecurrums Open Guestbook | 29/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Cjguestbook Project Cjguestbook | 24/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Cjguestbook | 24/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Mcguestbook | 23/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a… | |
| Modificada | Baja (2.6) | 1.2% | — | Myphp Guestbook | 19/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9)… | |
| Modificada | Baja (2.6) | 1.2% | — | Myphp Guestbook | 19/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in myPHP Guestbook 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Axentguestbook | 19/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.cfm in aXentGuestbook 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter. | |
| Modificada | Media (5.8) | 2.0% | — | Christian Becher Phazizguestbook | 13/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in phazizGuestbook 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) url fields, and (4) text field (content parameter). | |
| Modificada | Baja (2.6) | 2.2% | — | PBL Guestbook | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ibwd Guestbook | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |
| Modificada | Media (6.4) | 2.5% | 💥 Exploit | Hogstorps Hogstorp Guestbook | 2/6/2006 | 16/6/2026 | admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter. | |
| Modificada | Media (6.4) | 1.6% | — | Hogstorps Hogstorp Guestbook | 2/6/2006 | 16/6/2026 | admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.4% | — | Hogstorps Hogstorp Guestbook | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 1.2% | — | Xander Ladage Guestbookxl | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an IMG tag in a comment field to (1) guestwrite.php or (2) guestbook.php. | |
| Modificada | Media (4.3) | 1.7% | — | Chipmunk Scripts Chipmunk Guestbook | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in index.php, (b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d) edit.php. | |
| Modificada | Media (4.3) | 2.0% | — | Tuttophp Morris GuestbookTuttophp Pretty GuestbookTuttophp Smile Guestbook | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) Morris Guestbook 1, (2) Pretty Guestbook 1, and (3) Smile Guestbook 1 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the pagina parameter. |