Mavili-guestbook-project
4 CVEs tracked since 2012. Since Oct 2012, none of them reached CISA KEV.
Mavili-guestbook-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2012-10 | 4 | 0 |
Products
The products that kept showing up in Mavili-guestbook-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Mavili-guestbook-project.
- CVE-2012-5296Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) appr...4.3
- CVE-2012-5299Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.7.5
- CVE-2012-5297SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.7.5
- CVE-2012-5298Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.5.0
The record
- Peak rank
- #28 in Oct 2012
- Busiest month shown
- Oct 2012, 4 CVEs
- Months with a KEV entry
- 0 since Oct 2012
- Monthly snapshots
- 1 since 2012