Vulnerabilities > CVE-2007-1304 - Unspecified vulnerability in Savas Place Savas Guestbook 20061123
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://belsec.com/advisories/142/summary.html
- http://belsec.com/advisories/142/summary.html
- http://secunia.com/advisories/24411
- http://secunia.com/advisories/24411
- http://securityreason.com/securityalert/2350
- http://securityreason.com/securityalert/2350
- http://www.securityfocus.com/archive/1/461910/100/0/threaded
- http://www.securityfocus.com/archive/1/461910/100/0/threaded
- http://www.securityfocus.com/bid/22820
- http://www.securityfocus.com/bid/22820
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32811