Vulnerabilities > Deltascripts > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-05 | CVE-2008-0566 | Code Injection vulnerability in Deltascripts PHP Links 1.3 PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter. | 6.8 |
2008-02-05 | CVE-2008-0565 | SQL Injection vulnerability in Deltascripts PHP Links SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 6.8 |
2006-06-30 | CVE-2006-3330 | Input Validation vulnerability in Deltascripts PHP Classifieds 6.04 Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php. network deltascripts | 6.8 |
2006-06-07 | CVE-2006-2876 | Cross-Site Scripting vulnerability in PHP Pro Publish Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish 2.0 allows remote attackers to inject arbitrary web script or HTML via the catname parameter. network deltascripts | 6.8 |
2006-06-05 | CVE-2006-2821 | Cross-Site Scripting vulnerability in Deltascripts PRO Publish 2.0 Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php. network deltascripts | 6.8 |
2006-06-03 | CVE-2006-2803 | Cross-Site Scripting vulnerability in Deltascripts PHP Manualmaker 1.0 Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field. | 6.8 |
2006-05-01 | CVE-2006-2129 | SQL Injection vulnerability in Deltascripts PRO Publish 2.0 Direct static code injection vulnerability in Pro Publish 2.0 allows remote authenticated administrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php. | 5.5 |
2006-03-30 | CVE-2006-1532 | Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20 Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. network deltascripts | 4.3 |
2002-12-31 | CVE-2002-1702 | Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.0.5 Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter. network deltascripts | 4.3 |