Vulnerabilities > Martin Bauer > Gbook > 1.4

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2352 HTML Injection vulnerability in Martin Bauer Gbook 1.4
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.
network
martin-bauer
4.3
2004-12-31 CVE-2004-2351 HTML Injection vulnerability in Martin Bauer Gbook 1.4
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.
network
martin-bauer
4.3
2003-03-31 CVE-2002-1560 Unspecified vulnerability in Martin Bauer Gbook 1.4
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.
network
low complexity
martin-bauer
critical
10.0