Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2010-4914
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.
0
Attacker Value
Unknown
CVE-2010-4911
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
0
Attacker Value
Unknown
CVE-2008-7080
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
0
Attacker Value
Unknown
CVE-2009-2785
Disclosure Date: August 17, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
0
Attacker Value
Unknown
CVE-2008-5806
Disclosure Date: December 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-5805
Disclosure Date: December 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.
0
Attacker Value
Unknown
CVE-2008-2453
Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.
0
Attacker Value
Unknown
CVE-2008-0137
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
0
Attacker Value
Unknown
CVE-2007-6462
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-3160
Disclosure Date: June 11, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.
0