Vulnerabilities > Martin Bauer > Gbook

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4727 Cross-Site Scripting vulnerability in Gbook 1.0/1.0.1
Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.
network
high complexity
martin-bauer
5.1
2004-12-31 CVE-2004-2352 HTML Injection vulnerability in Martin Bauer Gbook 1.4
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.
network
martin-bauer
4.3
2004-12-31 CVE-2004-2351 HTML Injection vulnerability in Martin Bauer Gbook 1.4
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.
network
martin-bauer
4.3
2003-03-31 CVE-2002-1560 Unspecified vulnerability in Martin Bauer Gbook 1.4
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.
network
low complexity
martin-bauer
critical
10.0