📦

phpbb_advanced_guestbook

Vendor: phpbb_group

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 3.47% Exploit Prob.
Latest CVE CVE-2006-7076 Mar 02

Security Vulnerability Index

Page 1 / 1
4.3 CVSS

Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.

EPSS: 0.96%
6.8 CVSS

SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.

EPSS: 1.11%
7.5 CVSS
CVE-2006-2152
Exploit Found

PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

EPSS: 8.34%