Vulnerabilities > Prozilla

DATE CVE VULNERABILITY TITLE RISK
2009-02-11 CVE-2008-6115 SQL Injection vulnerability in Prozilla Hosting Index
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.
network
low complexity
prozilla CWE-89
7.5
2008-05-05 CVE-2008-2083 SQL Injection vulnerability in Prozilla Hosting Index
SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
network
prozilla CWE-89
6.8
2008-04-17 CVE-2008-1864 SQL Injection vulnerability in Prozilla Freelancers
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.
network
low complexity
prozilla CWE-89
7.5
2008-04-17 CVE-2008-1863 SQL Injection vulnerability in Prozilla Cheats 2.0
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
prozilla CWE-89
7.5
2008-04-15 CVE-2008-1789 SQL Injection vulnerability in Prozilla Forum
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
network
prozilla CWE-89
6.8
2008-04-15 CVE-2008-1788 SQL Injection vulnerability in Prozilla Entertainers 1.1
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
network
low complexity
prozilla CWE-89
7.5
2008-04-15 CVE-2008-1785 Improper Input Validation vulnerability in Prozilla TOP 100 1.2
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.
network
low complexity
prozilla CWE-20
5.5
2008-04-15 CVE-2008-1784 Permissions, Privileges, and Access Controls vulnerability in Prozilla Topsites 1.0
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
network
low complexity
prozilla CWE-264
7.5
2008-04-15 CVE-2008-1783 Permissions, Privileges, and Access Controls vulnerability in Prozilla Reviews 1.0
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.
network
low complexity
prozilla CWE-264
6.4
2007-08-15 CVE-2007-4362 SQL Injection vulnerability in Prozilla Webring Website Script Category.PHP
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter.
network
prozilla
6.8