VYPR

Opensource Guestbook

by Mgb

CVEs (2)

  • CVE-2018-25411HigMay 30, 2026
    risk 0.53cvss 8.2epss

    MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the…

  • CVE-2007-0354Jan 19, 2007
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.