Vulnerabilities > Fortunescripts

DATE CVE VULNERABILITY TITLE RISK
2017-12-27 CVE-2017-17904 Cross-site Scripting vulnerability in Fortunescripts Lynda Clone 1.0
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
network
low complexity
fortunescripts CWE-79
5.4
2017-12-27 CVE-2017-17903 Cross-Site Request Forgery (CSRF) vulnerability in Fortunescripts Lynda Clone 1.0
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
network
low complexity
fortunescripts CWE-352
8.8
2017-12-13 CVE-2017-17573 SQL Injection vulnerability in Fortunescripts Ebay Clone 1.0
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
network
low complexity
fortunescripts CWE-89
critical
9.8