Vulnerabilities > Radscripts

DATE CVE VULNERABILITY TITLE RISK
2010-03-10 CVE-2009-4697 Cross-Site Scripting vulnerability in Radscripts Radnics 5
Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter in a ulist action and the (2) fid parameter in a view_forum action.
network
radscripts CWE-79
4.3
2010-03-10 CVE-2009-4696 SQL Injection vulnerability in Radscripts Radnics 5
SQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.
network
low complexity
radscripts CWE-89
7.5
2010-03-10 CVE-2009-4695 SQL Injection vulnerability in Radscripts Radlance 7.5
SQL injection vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.
network
low complexity
radscripts CWE-89
7.5
2010-03-10 CVE-2009-4694 Cross-Site Scripting vulnerability in Radscripts Radlance 7.5
Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the fid parameter in a view_forum action.
network
radscripts CWE-79
4.3
2010-03-10 CVE-2009-4692 Cross-Site Scripting vulnerability in Radscripts Radlance 7.5
Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the pr parameter in a ulist action.
network
radscripts CWE-79
4.3
2009-10-02 CVE-2009-3530 Cross-Site Scripting vulnerability in Radscripts Radbids 4
Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
network
radscripts CWE-79
4.3
2009-10-02 CVE-2009-3529 SQL Injection vulnerability in Radscripts Radbids 4
SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074.
network
radscripts CWE-89
6.8
2009-07-27 CVE-2009-2599 SQL Injection vulnerability in Radscripts Radclassifieds 2.0
SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.
network
low complexity
radscripts CWE-89
7.5
2006-05-16 CVE-2006-2404 Local File Include vulnerability in Radscripts Radlance 7.0
Directory traversal vulnerability in popup.php in RadScripts RadLance Gold 7.0 allows remote attackers to read arbitrary files via a ..
network
low complexity
radscripts
6.4
2005-05-02 CVE-2005-1075 Multiple vulnerability in Radscripts Radbids 2
Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.
network
radscripts
4.3