Vulnerabilities > JAX Scripts

DATE CVE VULNERABILITY TITLE RISK
2009-12-29 CVE-2009-4447 Improper Authentication vulnerability in JAX Scripts JAX Guestbook 3.5.0
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
network
low complexity
jax-scripts CWE-287
7.5
2009-03-31 CVE-2008-6562 Cross-Site Scripting vulnerability in JAX Scripts JAX Linklists 1.00
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
4.3
2009-03-31 CVE-2005-4880 Permissions, Privileges, and Access Controls vulnerability in JAX Scripts JAX Guestbook 3.1/3.3.1
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
network
low complexity
jax-scripts CWE-264
5.0
2009-03-31 CVE-2005-4879 Cross-Site Scripting vulnerability in JAX Scripts JAX Guestbook 3.1/3.31
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters.
4.3
2007-01-18 CVE-2007-0335 Local File Include vulnerability in JAX Scripts JAX Petition Book 1.0.3.06
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a ..
network
jax-scripts
6.8
2006-04-20 CVE-2006-1913 Cross-Site Scripting vulnerability in Jax Guestbook Page Parameter
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
jax-scripts
6.8