Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2009-3601
Disclosure Date: October 08, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
0
Attacker Value
Unknown
CVE-2009-2551
Disclosure Date: July 20, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.
0
Attacker Value
Unknown
CVE-2009-0762
Disclosure Date: March 06, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-6112
Disclosure Date: February 11, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/.
0
Attacker Value
Unknown
CVE-2008-6090
Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
0
Attacker Value
Unknown
CVE-2008-6089
Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.
0
Attacker Value
Unknown
CVE-2008-5218
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
0
Attacker Value
Unknown
CVE-2008-2116
Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown
CVE-2008-2115
Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.
0
Attacker Value
Unknown
CVE-2006-7059
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (') in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.
0