Show filters
73 Total Results
Displaying 51-60 of 73
Sort by:
Attacker Value
Unknown

CVE-2010-5039

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-2670

Disclosure Date: July 08, 2010 (last updated October 04, 2023)
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2009-4883

Disclosure Date: June 11, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the (1) base_id or (2) course_id parameter in a search action.
0
Attacker Value
Unknown

CVE-2009-3694

Disclosure Date: October 13, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.
0
Attacker Value
Unknown

CVE-2008-7226

Disclosure Date: September 14, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.
0
Attacker Value
Unknown

CVE-2008-6943

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
0
Attacker Value
Unknown

CVE-2009-1662

Disclosure Date: May 18, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.
0
Attacker Value
Unknown

CVE-2008-6056

Disclosure Date: February 04, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to recipedetail.aspx, and the (3) catid parameter to validatefieldlength.aspx.
0
Attacker Value
Unknown

CVE-2008-4669

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-3322

Disclosure Date: July 25, 2008 (last updated October 04, 2023)
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.
0