Show filters
141 Total Results
Displaying 21-30 of 141
Sort by:
Attacker Value
Unknown

CVE-2021-24285

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.
Attacker Value
Unknown

CVE-2019-17228

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
Attacker Value
Unknown

CVE-2019-17229

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
Attacker Value
Unknown

CVE-2017-12757

Disclosure Date: May 09, 2019 (last updated November 27, 2024)
Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).
0
Attacker Value
Unknown

CVE-2017-17569

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
0
Attacker Value
Unknown

CVE-2017-17568

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
0
Attacker Value
Unknown

CVE-2017-17567

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
0
Attacker Value
Unknown

CVE-2017-17111

Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
0
Attacker Value
Unknown

CVE-2015-1477

Disclosure Date: February 04, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads.
0
Attacker Value
Unknown

CVE-2015-1478

Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds.
0