Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2009-3601

Disclosure Date: October 08, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
0
Attacker Value
Unknown

CVE-2009-2551

Disclosure Date: July 20, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.
0
Attacker Value
Unknown

CVE-2009-0762

Disclosure Date: March 06, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-6112

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/.
0
Attacker Value
Unknown

CVE-2008-6090

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
0
Attacker Value
Unknown

CVE-2008-6089

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.
0
Attacker Value
Unknown

CVE-2008-5218

Disclosure Date: November 25, 2008 (last updated October 04, 2023)
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
0
Attacker Value
Unknown

CVE-2008-2116

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown

CVE-2008-2115

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown

CVE-2006-7059

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (&#0000039) in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.
0