Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2010-4914

Disclosure Date: October 08, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.
0
Attacker Value
Unknown

CVE-2010-4911

Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
0
Attacker Value
Unknown

CVE-2008-7080

Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
0
Attacker Value
Unknown

CVE-2009-2785

Disclosure Date: August 17, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
0
Attacker Value
Unknown

CVE-2008-5806

Disclosure Date: December 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5805

Disclosure Date: December 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.
0
Attacker Value
Unknown

CVE-2008-2453

Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.
0
Attacker Value
Unknown

CVE-2008-0137

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
0
Attacker Value
Unknown

CVE-2007-6462

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-3160

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.
0