VYPR

ASP Guestbook

by Winn

CVEs (2)

  • CVE-2009-4760Mar 29, 2010
    risk 0.03cvss epss 0.03

    Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.

  • CVE-2009-4678Mar 8, 2010
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.