Vulnerabilities > Geodesicsolutions
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-05-27 | CVE-2014-3871 | SQL Injection vulnerability in Geodesicsolutions Geocore MAX 7.3.3 Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. | 7.5 |
2007-03-02 | CVE-2006-7072 | Cross-Site Scripting vulnerability in Geodesicsolutions Geoclassifieds Enterprise 2.0.5.0/2.0.5.1/2.0.5.2 Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b) admin/index.php, and (3) c[phone] parameter to register.php. network geodesicsolutions | 4.3 |
2006-07-25 | CVE-2006-3823 | SQL Injection vulnerability in Geodesicsolutions Geoauctions Premier and Geoclassifieds Basic SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. | 5.1 |
2006-07-25 | CVE-2006-3822 | SQL Injection vulnerability in Geodesicsolutions Geoauctions Enterprise 1.0.6 SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter. | 5.1 |