Vulnerabilities > Geodesicsolutions

DATE CVE VULNERABILITY TITLE RISK
2014-05-27 CVE-2014-3871 SQL Injection vulnerability in Geodesicsolutions Geocore MAX 7.3.3
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter.
network
low complexity
geodesicsolutions CWE-89
7.5
2007-03-02 CVE-2006-7072 Cross-Site Scripting vulnerability in Geodesicsolutions Geoclassifieds Enterprise 2.0.5.0/2.0.5.1/2.0.5.2
Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b) admin/index.php, and (3) c[phone] parameter to register.php.
4.3
2006-07-25 CVE-2006-3823 SQL Injection vulnerability in Geodesicsolutions Geoauctions Premier and Geoclassifieds Basic
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.
network
high complexity
geodesicsolutions CWE-89
5.1
2006-07-25 CVE-2006-3822 SQL Injection vulnerability in Geodesicsolutions Geoauctions Enterprise 1.0.6
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter.
network
high complexity
geodesicsolutions
5.1