DMSGuestbook <= 1.7.0 - SQL Injection
high
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
- CVSS:
- 7.2
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Feb 2, 2008
CVE-2008-0616 on NVD →
DMSGuestbook < 1.9.0 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.
- CVSS:
- 6.1
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Feb 2, 2008
CVE-2008-0617 on NVD →
DMSGuestbook < 1.9.0 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown; th...
- CVSS:
- 6.1
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Feb 2, 2008
CVE-2008-0618 on NVD →
DMSGuestbook <= 1.8.0 - Directory Traversal
medium
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.
- CVSS:
- 5.3
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Feb 2, 2008
CVE-2008-0615 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database