VendorsAspjaraspjar_guestbookall versions
Vulnerabilities

Aspjar Aspjar Guestbook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2002-1729
Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.
Published 2005-06-21 · Modified
6.8EPSS 0.013
CVE-2002-1730
ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true".
Published 2005-06-21 · Modified
5.0EPSS 0.014
CVE-2005-0424
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.
Published 2005-02-15 · Modified
5.0EPSS 0.014
CVE-2005-0423
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.
Published 2005-02-15 · Modified
5.0EPSS 0.012