Vulnerabilities > Scriptphp

DATE CVE VULNERABILITY TITLE RISK
2008-05-16 CVE-2008-2280 Cross-Site Scripting vulnerability in Scriptphp Picengine 1.0
Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.
network
scriptphp CWE-79
4.3
2006-12-15 CVE-2006-6580 Authentication Bypass vulnerability in Scriptphp Pronews 1.5
admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other impacts.
network
low complexity
scriptphp
6.4
2006-12-14 CVE-2006-6521 Input Validation vulnerability in Scriptphp Messageriescripthp 2.0
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
network
low complexity
scriptphp
7.5
2006-12-14 CVE-2006-6520 Input Validation vulnerability in Scriptphp Messageriescripthp 2.0
Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.
network
scriptphp
6.8
2006-12-14 CVE-2006-6519 Input Validation vulnerability in Scriptphp Pronews 1.5
SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
network
low complexity
scriptphp
7.5
2006-12-14 CVE-2006-6518 Input Validation vulnerability in Scriptphp Pronews 1.5
Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php, and the (8) aa parameter to (b) lire-avis.php.
network
scriptphp
6.8
2006-12-12 CVE-2006-6480 Input Validation vulnerability in Scriptphp Annoncescripthp 2.0
admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.
network
low complexity
scriptphp
5.0
2006-12-12 CVE-2006-6479 Input Validation vulnerability in Scriptphp Annoncescripthp 2.0
Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php.
network
scriptphp
6.8
2006-12-12 CVE-2006-6478 Input Validation vulnerability in Scriptphp Annoncescripthp 2.0
Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d) admin/admin_annonce/okvalannonce.php and (e) admin/admin_annonce/changeannonce.php.
network
low complexity
scriptphp
7.5