CVE Certified
GHDB

intitle:guestbook "advanced guestbook 2.2 powered"

prev next

Google search: intitle:guestbook "advanced guestbook 2.2 powered"

Hits: 3571

Submited: 2004-05-12

Advanced Guestbook v2.2 has an SQL injection problem which allows unauthorized access. AttackerFrom there, hit "Admin" then do the following:Leave username field blank.For password, enter this exactly:') OR ('a' = 'aYou are now in the Guestbook's Admin section.http://www.securityfocus.com/bid/10209