Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2020-25950
Disclosure Date: January 08, 2021 (last updated February 22, 2025)
Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.
0
Attacker Value
Unknown
CVE-2011-0510
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.
0
Attacker Value
Unknown
CVE-2008-2903
Disclosure Date: June 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.
0
Attacker Value
Unknown
CVE-2007-4113
Disclosure Date: July 31, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Advanced Webhost Billing System (AWBS) before 2.6.0 allows remote authenticated users to obtain configuration data about other dedicated servers via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4112
Disclosure Date: July 31, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."
0
Attacker Value
Unknown
CVE-2007-2272
Disclosure Date: April 25, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.
0
Attacker Value
Unknown
CVE-2006-3956
Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters.
0