CVE-2012-5299 Information

Description

Mavili Guestbook as released in November 2007 allows remote attackers to edit delete and approve arbitrary messages via a direct request to (1) edit.asp (2) delete.asp or (3) approve.asp.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-01/0010.html http://code.google.com/p/maviliguestbook/issues/detail?id=1 http://www.securityfocus.com/bid/51252 https://exchange.xforce.ibmcloud.com/vulnerabilities/72099

Share on: