plugin

Dmsguestbook Vulnerabilities

4 known security issues reported for the Dmsguestbook WordPress plugin. Most recent disclosed Feb 2, 2008.

1 high 3 medium

Running Dmsguestbook on your site? Check whether your installed version is affected.

Scan your site free

DMSGuestbook <= 1.7.0 - SQL Injection

high

SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

CVSS:
7.2
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Feb 2, 2008

CVE-2008-0616 on NVD →

DMSGuestbook < 1.9.0 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.

CVSS:
6.1
Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
Feb 2, 2008

CVE-2008-0617 on NVD →

DMSGuestbook < 1.9.0 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown; th...

CVSS:
6.1
Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
Feb 2, 2008

CVE-2008-0618 on NVD →

DMSGuestbook <= 1.8.0 - Directory Traversal

medium

Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.

CVSS:
5.3
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Feb 2, 2008

CVE-2008-0615 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database