5
CVSSv2

CVE-2005-4880

Published: 31/03/2009 Updated: 31/03/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 520
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jax scripts jax guestbook 3.3.1

jax scripts jax guestbook 3.1

Exploits

source: wwwsecurityfocuscom/bid/14482/info Jax PHP Scripts are affected by multiple cross-site scripting vulnerabilities These issues are due to a failure in the applications to properly sanitize user-supplied input An attacker may leverage any of these issues to have arbitrary script code executed in the browser ...
source: wwwsecurityfocuscom/bid/14482/info Jax PHP Scripts are affected by multiple cross-site scripting vulnerabilities These issues are due to a failure in the applications to properly sanitize user-supplied input An attacker may leverage any of these issues to have arbitrary script code executed in the browser of a ...
source: wwwsecurityfocuscom/bid/14482/info Jax PHP Scripts are affected by multiple cross-site scripting vulnerabilities These issues are due to a failure in the applications to properly sanitize user-supplied input An attacker may leverage any of these issues to have arbitrary script code executed in the browser of ...
source: wwwsecurityfocuscom/bid/14482/info Jax PHP Scripts are affected by multiple cross-site scripting vulnerabilities These issues are due to a failure in the applications to properly sanitize user-supplied input An attacker may leverage any of these issues to have arbitrary script code executed in the browser of an ...