Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2008-7080
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
0
Attacker Value
Unknown
CVE-2009-2785
Disclosure Date: August 17, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
0
Attacker Value
Unknown
CVE-2008-2453
Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.
0