Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.
References
Configurations
History
No history.
Information
Published : 2007-03-07 00:19
Updated : 2024-02-14 01:17
NVD link : CVE-2007-1304
Mitre link : CVE-2007-1304
CVE.ORG link : CVE-2007-1304
JSON object : View
Products Affected
savas_place
- savas_guestbook
CWE