Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2020-25950

Disclosure Date: January 08, 2021 (last updated February 22, 2025)
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
Attacker Value
Unknown

CVE-2011-0510

Disclosure Date: January 20, 2011 (last updated October 04, 2023)
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
0
Attacker Value
Unknown

CVE-2008-2903

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.
0
Attacker Value
Unknown

CVE-2007-4113

Disclosure Date: July 31, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Advanced Webhost Billing System (AWBS) before 2.6.0 allows remote authenticated users to obtain configuration data about other dedicated servers via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4112

Disclosure Date: July 31, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."
0
Attacker Value
Unknown

CVE-2007-2272

Disclosure Date: April 25, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.
0
Attacker Value
Unknown

CVE-2006-3956

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters.
0