2008.08.21

Mambo 4.6.2 Multiple vulnerabilities

Multiple vulnerabilities have been identified in Mambo 4.6.2 which could lead to SQL injections, cross-site scripting, cross-site request forgery attacks, spamming and brute forcing administrator access.

2007.09.27

Scite Text Editor v1.71 Null-pointer dereference

2006.12.05

aBitWhizzy PHP Directory Traversal Vulnerability

A vulnerability was reported in aBitWhizzy. A remote user can include and execute local files on the target system.

2006.11.24

JiRos Links Manager SQL Injections and Cross-Site Scripting Attacks

A vulnerability was reported in JiRo's Link Manager. A remote user can injection SQL commands. A remote user can conduct cross-site scripting attacks.

2006.11.21

Link Exchange Lite SQL Injections Attacks

Multiple vulnerabilities have been identified in SoftAcid Link Exchange Lite, which could be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in the "search.asp" and "linkslist.asp" scripts that do not validate the "url" and "psearch" parameters before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.

2006.11.21

CreaDirectory Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in CreaDirectory have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.21

Classified System 2004 Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in Classified System 2004 have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.20

Rialto 1.x Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in Rialto have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.20

Enthrallweb eHomes Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in Enthrallweb eHomes have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.19

The Classified Ad System Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in The Classifieds Ad System have been reported, which can be exploited by remote users conduct SQL injection and cross-site scripting vulnerabilities.

2006.11.19

Rapid Classified 3.1 Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in Rapid Classified have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.19

Enthrallweb eClassifieds Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in Enthrallweb eClassifieds have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.18

Vikingboard 0.1.2 Remote Cross-Site Scripting and Arbitrary File Inclusion Vulnerabilities

Multiple input validation vulnerabilities in Vikingboard have been reported, which can be exploited by remote users to disclose certain sensitive information and conduct script insertion attacks.

2006.11.17

BestWebApp Dating Site Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple input validation vulnerabilities in BestWebApp Dating Site have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.17

ASPCart 4.x Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Some vulnerabilities in ASPCart have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.17

20/20 Auto GalleryRemote Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Multiple vulnerabilities in 20/20 Auto Gallery have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.16

phpMyAdmin 2.9.1 Table Comment Remote Cross-Site Scripting Vulnerability

A vulnerability in phpMyAdmin have been reported, which can be exploited by remote users to conduct cross-site scripting attacks.

2006.11.15

E-Calendar Pro 3.0 Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Some vulnerabilities in E-Calendar Pro have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.15

Dragon Internet Events Listing 2.x Multiple Parameter Handling Remote SQL Injection Vulnerability

Some vulnerabilities in Dragon Internet Events Listing have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.14

Inventory Manager Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Cross Site Scripting, Manipulation of data

2006.11.14

Hpecs Shopping Cart Multiple SQL Injection Vulnerabilities

Some vulnerabilities in Hpecs Shopping Cart, which can be exploited by malicious people to conduct SQL injection attacks.

2006.11.14

FunkyASP Glossary 1.0 SQL Injection Vulnerability

Some vulnerabilities in FunkyASP Glossary 1.0, which can be exploited by malicious people to conduct SQL injection attacks.

2006.11.14

Enthrallweb eShopping Cart Multiple Parameter Handling Remote SQL Injection Vulnerability

Some vulnerabilities in Enthrallweb eShopping Cart have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.14

E-commerce Kit-1 PayPal Edition Multiple SQL Injections

Some vulnerabilities in E-commerce Kit-1 PayPal Edition, which can be exploited by malicious people to conduct SQL injection attacks.

2006.11.14

Car Site Manager Remote SQL Injection And Cross-Site Scripting Vulnerabilities

Some vulnerabilities in Car Site Manager, which can be exploited by malicious people to conduct SQL injection attacks and cross-site scripting attacks.

2006.11.14

CandyPress Store 'policy' and 'brand' Parameter Handling Remote SQL Injection Vulnerabilities

Some vulnerabilities in CandyPress Store have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.14

BlogMe Script 3 SQL Injections and Cross-Site Scripting Attacks

Some vulnerabilities in BlogMe, which can be exploited by malicious people to conduct script insertion and SQL injection attacks.

2006.11.14

A+ Store E-Commerce SQL Injection and Cross-Site Scripting

Two vulnerabilities in A+ Store E-Commerce have been reported, which can be exploited by remote users to conduct SQL injection and cross-site scripting attacks.

2006.11.13

myStats Multiple Parameter Handling Remote SQL Injection And Cross-Site Scripting Vulnerabilities

Two input validation vulnerabilities in myStats have been reported, which can be exploited by remote users to conduct SQL injection and cross-site scripting attacks.

2006.11.12

INFINICART Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Two vulnerabilities in INFINICART have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.10

OmniStar Article Multiple Parameter Handling Remote SQL Injection Vulnerabilities

Multiple vulnerabilities in OmniStar Article have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.09

Wheatblog 1.x Comment Multiple Paramater Handling Remote Cross-Site Scripting Vulnerability

Multiple input validation vulnerabilities in Wheatblog have been reported, which can be exploited by remote users or users to conduct script insertion attacks.

2006.11.09

SpeedyWiki 2.0 File Upload And Cross-Site Scripting Vulnerabilities

Two vulnerabilities in SpeedyWiki have been reported, which can be exploited by remote users to compromise a vulnerable system and to conduct cross-site scripting attacks.

2006.11.09

LandShop Multiple Parameter Handling Remote Cross-Site Scripting and SQL Injection Vulnerabilities

Multiple vulnerabilities in Landshop have been reported, which can be exploited by remote users to conduct cross-site scripting and SQL injection attacks.

2006.11.09

FreeWebshop Script 2.2.2 Local File Inclusion and Cross-Site Scripting Vulnerabilities

Two vulnerabilities in FreeWebshop.org Script have been reported, which can be exploited by remote users to disclose sensitive information or conduct cross-site scripting attacks.

2006.11.09

Bitweaver 1.3.1 Remote SQL Injection and Cross-Site Scripting Vulnerabilities

Two input validation vulnerabilities in bitweaver have been reported, which can be exploited by remote users to conduct SQL injection and cross-site scripting attacks.

2006.11.09

All In One Control Panel (AIOCP) 1.3.007 Multiple SQL Injection and Cross Site Scripting Vulnerabilities

Multiple vulnerabilities in All In One Control Panel (AIOCP) have been reported, which can be exploited by remote users to conduct SQL injection attacks or cross-site scripting attacks.

2006.11.08

Portix-PHP SQL Injection Attack to bypass authentification and Cross-Site Scripting Attack

SQL Injection allowing hacker to bypass login authentification and cross site scripting attacks

2006.11.08

Abarcar Realty Portal 'neid' and 'slid' Paramater Handling Remote SQL Injection Vulnerabilities

Some vulnerabilities in Abarcar Realty Portal have been reported, which can be exploited by remote users to conduct SQL injection attacks.

2006.11.06

If-CMS Missing Input Validation in 'rns' Parameter Permits Cross-Site Scripting Attacks

A vulnerability was reported in If-CMS. A remote user can conduct cross-site scripting attacks.