Syguestbook A5 Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-13950

    index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.

    Last Modified: Nov 21, 2024
    Published: Jul 18, 2019

    CVE-2019-13949

    SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.

    Last Modified: Nov 21, 2024
    Published: Jul 18, 2019

    CVE-2019-13948

    SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element.

    Last Modified: Nov 21, 2024
    Published: Jul 18, 2019
    Items Per Page
    Syguestbook_A5_Project Vulnerabilities & Security CVEs | CVE-DB