Show filters
141 Total Results
Displaying 31-40 of 141
Sort by:
Attacker Value
Unknown
CVE-2014-100020
Disclosure Date: January 13, 2015 (last updated October 05, 2023)
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.
0
Attacker Value
Unknown
CVE-2014-10013
Disclosure Date: January 13, 2015 (last updated September 26, 2024)
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
0
Attacker Value
Unknown
CVE-2014-10012
Disclosure Date: January 13, 2015 (last updated September 26, 2024)
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
0
Attacker Value
Unknown
CVE-2014-2024
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/.
0
Attacker Value
Unknown
CVE-2013-7216
Disclosure Date: December 24, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.
0
Attacker Value
Unknown
CVE-2012-5823
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown
CVE-2012-4874
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads."
0
Attacker Value
Unknown
CVE-2012-0990
Disclosure Date: February 07, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.
0
Attacker Value
Unknown
CVE-2010-4914
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.
0
Attacker Value
Unknown
CVE-2010-4911
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
0