Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2007-1617

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
0
Attacker Value
Unknown

CVE-2007-1619

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter.
0
Attacker Value
Unknown

CVE-2007-1616

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter.
0
Attacker Value
Unknown

CVE-2007-1615

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
0
Attacker Value
Unknown

CVE-2007-1618

Disclosure Date: March 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
0
Attacker Value
Unknown

CVE-2007-0335

Disclosure Date: January 18, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
0
Attacker Value
Unknown

CVE-2006-3950

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2006-3959

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.
0
Attacker Value
Unknown

CVE-2006-3960

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-2281

Disclosure Date: May 10, 2006 (last updated October 04, 2023)
X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it.
0