Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields.
References
Configurations
History
21 Nov 2024, 00:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://it.security.netsons.org/exploit/MicroGuestBook.txt - | |
References | () http://secunia.com/advisories/21155 - | |
References | () http://securityreason.com/securityalert/1285 - | |
References | () http://www.osvdb.org/28677 - | |
References | () http://www.securityfocus.com/archive/1/440855/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/19119 - | |
References | () http://www.vupen.com/english/advisories/2006/2935 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27911 - |
Information
Published : 2006-07-25 23:04
Updated : 2024-11-21 00:14
NVD link : CVE-2006-3852
Mitre link : CVE-2006-3852
CVE.ORG link : CVE-2006-3852
JSON object : View
Products Affected
phptoys
- micro_guestbook
CWE