Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.
References
Configurations
History
21 Nov 2024, 00:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://belsec.com/advisories/142/summary.html - URL Repurposed | |
References | () http://secunia.com/advisories/24411 - | |
References | () http://securityreason.com/securityalert/2350 - | |
References | () http://www.securityfocus.com/archive/1/461910/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/22820 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/32811 - |
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://belsec.com/advisories/142/summary.html - URL Repurposed |
Information
Published : 2007-03-07 00:19
Updated : 2024-11-21 00:28
NVD link : CVE-2007-1304
Mitre link : CVE-2007-1304
CVE.ORG link : CVE-2007-1304
JSON object : View
Products Affected
savas_place
- savas_guestbook
CWE