Extension WordPress
Vulnérabilités DMSGuestbook
Cette page rassemble les failles publiées pour DMSGuestbook, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de DMSGuestbook
4 fiches
DMSGuestbook < 1.9.0 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified…
[*, 1.9.0)
1.9.0
02/02/2008
DMSGuestbook <= 1.8.0 – Directory Traversal
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.
*-1.8.0
1.8.1
02/02/2008
DMSGuestbook < 1.9.0 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page,…
[*, 1.9.0)
1.9.0
02/02/2008
DMSGuestbook <= 1.7.0 – SQL Injection
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
*
Non indiqué
02/02/2008
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.