Show filters
141 Total Results
Displaying 31-40 of 141
Sort by:
Attacker Value
Unknown

CVE-2014-100020

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.
0
Attacker Value
Unknown

CVE-2014-10013

Disclosure Date: January 13, 2015 (last updated September 26, 2024)
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
0
Attacker Value
Unknown

CVE-2014-10012

Disclosure Date: January 13, 2015 (last updated September 26, 2024)
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
0
Attacker Value
Unknown

CVE-2014-2024

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/.
0
Attacker Value
Unknown

CVE-2013-7216

Disclosure Date: December 24, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.
0
Attacker Value
Unknown

CVE-2012-5823

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown

CVE-2012-4874

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads."
0
Attacker Value
Unknown

CVE-2012-0990

Disclosure Date: February 07, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.
0
Attacker Value
Unknown

CVE-2010-4914

Disclosure Date: October 08, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.
0
Attacker Value
Unknown

CVE-2010-4911

Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
0