Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ades Design Adesguestbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Advanced Guestbook | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548. | |
| Modificada | Media (4.3) | 1.2% | — | Epistream Ipei Guestbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook. | |
| Modificada | Alta (7.5) | 1.2% | — | Advanced Guestbook | 16/11/2005 | 16/6/2026 | SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field. | |
| Modificada | Media (5) | 1.4% | — | Chipmunk Scripts Chipmunk Guestbook | 6/11/2005 | 16/6/2026 | Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php. | |
| Modificada | Media (4.3) | 1.2% | — | Emefa Guestbook | 23/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Levcgi.com Myguestbook | 6/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Episodex Guestbook | 20/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields. | |
| Modificada | Alta (7.5) | 1.7% | — | Episodex Guestbook | 20/5/2005 | 16/6/2026 | episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp. | |
| Modificada | Alta (7.5) | 1.7% | — | Htmljunction Ezguestbook | 18/5/2005 | 16/6/2026 | HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Soren Boysen Skull-splitter Guestbook | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Advanced Guestbook | 14/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Pixysoft Guestbook PRO | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. | |
| Modificada | Media (5) | 1.5% | — | Uapplication Uguestbook | 3/5/2005 | 16/6/2026 | Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb. | |
| Modificada | Alta (7.5) | 1.2% | — | Abczone.it Wwwguestbook | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ecomm Professional Guestbook | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Webmasters-debutants WD Guestbook | 2/5/2005 | 16/6/2026 | Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php. | |
| Modificada | Media (5) | 1.2% | — | Aspjar Guestbook | 27/4/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Modificada | Media (5) | 1.4% | — | Aspjar Guestbook | 27/4/2005 | 16/6/2026 | Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730. | |
| Modificada | Media (4.3) | 0.96% | — | HPM Guestbook.cgi | 30/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Advanced Guestbook | 10/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | Alexphpteam Alex Guestbook | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 1.5% | — | Abczone.it Wwwguestbook | 31/12/2004 | 16/6/2026 | Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password. | |
| Modificada | Media (6.8) | 1.5% | — | Francisco Burzi Php-nukeWarpspeed 4nguestbook | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Advanced Guestbook | 23/4/2004 | 16/6/2026 | SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password. |