CVE-2010-4987
Published Nov 1, 2011SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
Vendor archive
2 CVEs tagged to vendor kmsoft — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direc…