Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2010-4770

Disclosure Date: March 23, 2011 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
0
Attacker Value
Unknown

CVE-2010-0763

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action.
0
Attacker Value
Unknown

CVE-2010-0761

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.
0
Attacker Value
Unknown

CVE-2010-0762

Disclosure Date: March 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
0
Attacker Value
Unknown

CVE-2010-0693

Disclosure Date: February 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2010-0690

Disclosure Date: February 23, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.
0
Attacker Value
Unknown

CVE-2005-3917

Disclosure Date: November 30, 2005 (last updated February 22, 2025)
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
0