Vulnerabilities > JAX Scripts
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-12-29 | CVE-2009-4447 | Improper Authentication vulnerability in JAX Scripts JAX Guestbook 3.5.0 Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php. | 7.5 |
2009-03-31 | CVE-2008-6562 | Cross-Site Scripting vulnerability in JAX Scripts JAX Linklists 1.00 Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | 4.3 |
2009-03-31 | CVE-2005-4880 | Permissions, Privileges, and Access Controls vulnerability in JAX Scripts JAX Guestbook 3.1/3.3.1 Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv. | 5.0 |
2009-03-31 | CVE-2005-4879 | Cross-Site Scripting vulnerability in JAX Scripts JAX Guestbook 3.1/3.31 Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. | 4.3 |
2007-01-18 | CVE-2007-0335 | Local File Include vulnerability in JAX Scripts JAX Petition Book 1.0.3.06 Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. network jax-scripts | 6.8 |
2006-04-20 | CVE-2006-1913 | Cross-Site Scripting vulnerability in Jax Guestbook Page Parameter Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter. network jax-scripts | 6.8 |