VendorsSavas Placesavas_guestbook2006-11-23
Vulnerabilities

Savas Place Savas Guestbook 2006-11-23

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2007-1305
Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.
Published 2007-03-07 · Modified
6.8EPSS 0.014
CVE-2007-1304
Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.
Published 2007-03-07 · Modified
6.8EPSS 0.012