Vulnerabilities > Deltascripts > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-02-05 CVE-2008-0566 Code Injection vulnerability in Deltascripts PHP Links 1.3
PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter.
6.8
2008-02-05 CVE-2008-0565 SQL Injection vulnerability in Deltascripts PHP Links
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
6.8
2006-06-30 CVE-2006-3330 Input Validation vulnerability in Deltascripts PHP Classifieds 6.04
Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.
network
deltascripts
6.8
2006-06-07 CVE-2006-2876 Cross-Site Scripting vulnerability in PHP Pro Publish
Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish 2.0 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.
network
deltascripts
6.8
2006-06-05 CVE-2006-2821 Cross-Site Scripting vulnerability in Deltascripts PRO Publish 2.0
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
network
deltascripts
6.8
2006-06-03 CVE-2006-2803 Cross-Site Scripting vulnerability in Deltascripts PHP Manualmaker 1.0
Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field.
6.8
2006-05-01 CVE-2006-2129 SQL Injection vulnerability in Deltascripts PRO Publish 2.0
Direct static code injection vulnerability in Pro Publish 2.0 allows remote authenticated administrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php.
network
low complexity
deltascripts
5.5
2006-03-30 CVE-2006-1532 Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20
Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.
network
deltascripts
4.3
2002-12-31 CVE-2002-1702 Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.0.5
Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.
network
deltascripts
4.3