Vulnerabilities > Dieselscripts

DATE CVE VULNERABILITY TITLE RISK
2009-03-13 CVE-2008-6468 SQL Injection vulnerability in Dieselscripts Diesel PAY
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action.
network
low complexity
dieselscripts CWE-89
7.5
2009-03-13 CVE-2008-6467 SQL Injection vulnerability in Dieselscripts Diesel JOB Site
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.
network
low complexity
dieselscripts CWE-89
7.5
2008-09-24 CVE-2008-4150 SQL Injection vulnerability in Dieselscripts Diesel Joke Site
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.
network
low complexity
dieselscripts CWE-89
7.5
2006-08-27 CVE-2006-4362 Cross-Site Scripting vulnerability in DieselScripts Diesel Paid Mail Getad.PHP
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter.
network
dieselscripts
4.3
2006-08-27 CVE-2006-4361 Cross-Site Scripting vulnerability in Diesel Job Site
Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.
network
dieselscripts
4.3
2006-08-27 CVE-2006-4358 Cross-Site Scripting vulnerability in DieselScripts Diesel Pay
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter.
network
dieselscripts
4.3
2006-08-27 CVE-2006-4357 Remote File Include vulnerability in DieselScripts Smart Traffic
PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter.
network
low complexity
dieselscripts
7.5
2006-07-21 CVE-2006-3763 SQL Injection vulnerability in Dieselscripts Diesel Joke Site 2.0
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
dieselscripts
7.5
2006-05-23 CVE-2006-2540 Information Disclosure vulnerability in Diesel Job Site
Privacy leak in install.php for Diesel PHP Job Site sends sensitive information such as user credentials to an e-mail address controlled by the product developers.
network
low complexity
dieselscripts
5.0