Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2017-10898
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-0531
Disclosure Date: February 11, 2009 (last updated October 04, 2023)
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
0
Attacker Value
Unknown
CVE-2008-0289
Disclosure Date: January 16, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."
0
Attacker Value
Unknown
CVE-2007-5752
Disclosure Date: October 31, 2007 (last updated October 04, 2023)
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.
0
Attacker Value
Unknown
CVE-2006-2687
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).
0