Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2007-2805

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.
0
Attacker Value
Unknown

CVE-2005-4630

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters.
0
Attacker Value
Unknown

CVE-2004-1590

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.
0