Advanced Guestbook is a web-based guestbook application that has accumulated vulnerabilities primarily classified under broad categories rather than specific, well-defined weakness patterns. The vendor's disclosure history shows a tendency toward public exploit code availability, reflecting the application's accessibility as a web-facing comment system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advanced Guestbook over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1952HIGH SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password. | Apr 23, 2004 | 7.5 | 34 | NO | YES |
CVE-2005-1548HIGH SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter. | May 14, 2005 | 7.5 | 29 | NO | YES |
CVE-2004-1213MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML v | Jan 10, 2005 | 6.8 | 27 | NO | YES |
CVE-2007-0609MEDIUM Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local te | May 9, 2007 | 5.1 | 25 | NO | YES |
CVE-2007-0605MEDIUM Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter. | May 9, 2007 | 4.3 | 23 | NO | YES |
CVE-2005-3588HIGH SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field. | Nov 16, 2005 | 7.5 | 21 | NO | NO |
CVE-2006-5804HIGH PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | Nov 8, 2006 | 7.5 | 20 | NO | NO |
CVE-2007-0608HIGH Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal th | May 9, 2007 | 7.1 | 19 | NO | NO |
CVE-2007-0530HIGH Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) i | Jan 26, 2007 | 7.5 | 19 | NO | NO |
CVE-2005-4649MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advanced Guestbook.
Media articles that mention a CVE ID that affects a product developed by Advanced Guestbook — matched by CVE ID, not by vendor name.