Vulnerabilities > FAD Solutions

DATE CVE VULNERABILITY TITLE RISK
2005-12-20 CVE-2005-4367 Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2
Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the "Domain Availability" field.
network
fad-solutions
5.8
2005-12-20 CVE-2005-4366 SQL Injection vulnerability in FAD Solutions Drzes HMS 3.2
Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php; (2) the customerPlanID parameter to viewplan.php; (3) the ref_id parameter to referred_plans.php; (4) customerPlanID parameter to listcharges.php; and (5) the domain parameter to (k) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php.
network
low complexity
fad-solutions
6.4
2005-12-09 CVE-2005-4137 Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2
SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.
network
low complexity
fad-solutions
7.5
2005-12-09 CVE-2005-4136 Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
network
fad-solutions
4.3