Vulnerabilities > Discountedscripts

DATE CVE VULNERABILITY TITLE RISK
2008-09-24 CVE-2008-4144 SQL Injection vulnerability in Discountedscripts E-Gold Script Shop
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action.
network
low complexity
discountedscripts CWE-89
7.5
2008-09-05 CVE-2008-3944 SQL Injection vulnerability in Discountedscripts ACG PTP 1.0.6
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.
network
low complexity
discountedscripts CWE-89
7.5
2008-08-26 CVE-2008-3782 Cross-Site Scripting vulnerability in Discountedscripts ACG PTP 1.0.6
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ Entry.
3.5
2008-08-21 CVE-2008-3765 SQL Injection vulnerability in Discountedscripts Quick Poll Script
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
discountedscripts CWE-89
7.5