CVE Vulnerabilities

CVE-2007-1304

Published: Mar 07, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in add2.php in Savas Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.

Affected Software

Name Vendor Start Version End Version
Savas_guestbook Savas_place 2006-11-23 (including) 2006-11-23 (including)

References