Vulnerabilities
Vulnerable Software
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
CVSS Score
7.5
EPSS Score
0.005
Published
2009-03-02
Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in index.php, (b) newtopic.php, and (c) reply.php; and (3) ID parameter to (d) edit.php.
CVSS Score
4.3
EPSS Score
0.008
Published
2006-06-02
SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name.
CVSS Score
7.5
EPSS Score
0.016
Published
2006-04-11
Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.
CVSS Score
4.3
EPSS Score
0.004
Published
2006-01-03
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
CVSS Score
5.0
EPSS Score
0.005
Published
2005-11-06


Contact Us

Shodan ® - All rights reserved