Vulnerabilities > Ordasoft

DATE CVE VULNERABILITY TITLE RISK
2018-02-17 CVE-2018-5982 SQL Injection vulnerability in Ordasoft Advertisement Board 3.1.0
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.
network
low complexity
ordasoft CWE-89
7.5
2018-02-17 CVE-2018-5971 SQL Injection vulnerability in Ordasoft Medialibrary 4.0.12
SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
network
low complexity
ordasoft CWE-89
7.5
2010-07-25 CVE-2010-2851 SQL Injection vulnerability in Ordasoft COM Booklibrary 1.5
SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
network
low complexity
ordasoft joomla CWE-89
7.5
2010-07-02 CVE-2010-1522 SQL Injection vulnerability in Ordasoft COM Booklibrary 1.5.3
Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lend_request or (2) save_lend_request action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.
network
low complexity
ordasoft joomla CWE-89
7.5
2009-10-28 CVE-2009-3817 Code Injection vulnerability in Ordasoft COM Booklibrary 1.0
PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637.
network
low complexity
joomla ordasoft CWE-94
7.5
2009-07-28 CVE-2009-2637 Code Injection vulnerability in Ordasoft COM Booklibrary 1.5.2.4
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
network
low complexity
joomla ordasoft CWE-94
7.5
2009-07-28 CVE-2009-2635 Code Injection vulnerability in Ordasoft COM Realestatemanager 1.0
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
network
low complexity
joomla ordasoft CWE-94
7.5
2009-07-28 CVE-2009-2634 Code Injection vulnerability in Ordasoft COM Medialibrary 1.5.3
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
network
low complexity
joomla ordasoft CWE-94
7.5
2009-07-28 CVE-2009-2633 Code Injection vulnerability in Ordasoft COM Vehiclemanager 1.0
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
network
low complexity
joomla ordasoft CWE-94
7.5