VendorsEmefaemefa_guestbookall versions
Vulnerabilities

Emefa Emefa Guestbook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-5852
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
Published 2009-01-06 · Modified
5.01 PoCEPSS 0.026
CVE-2005-2650
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
Published 2005-08-21 · Modified
4.3EPSS 0.012