Vulnerabilities > Softbiz

DATE CVE VULNERABILITY TITLE RISK
2009-08-17 CVE-2009-2790 SQL Injection vulnerability in Softbiz Dating Script
SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
network
low complexity
softbiz CWE-89
7.5
2008-08-07 CVE-2008-3511 Cross-Site Scripting vulnerability in Softbiz Image Gallery
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/.
network
softbiz CWE-79
4.3
2008-05-06 CVE-2008-2087 SQL Injection vulnerability in Softbiz web Hosting Directory Script
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
network
softbiz CWE-89
6.8
2008-02-27 CVE-2008-1050 SQL Injection vulnerability in Softbiz Jokes and Funny Pictures Script
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
network
low complexity
softbiz CWE-89
7.5
2007-11-26 CVE-2007-6125 SQL Injection vulnerability in Softbiz Freelancers Script 1.0
SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
network
low complexity
softbiz CWE-89
7.5
2007-11-26 CVE-2007-6124 Cross-Site Scripting vulnerability in Softbiz Freelancers Script 1.0
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.
network
softbiz CWE-79
4.3
2007-10-14 CVE-2007-5449 SQL Injection vulnerability in Softbiz Recipes Portal Script
SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
network
low complexity
softbiz CWE-89
7.5
2006-06-28 CVE-2006-3271 SQL Injection vulnerability in Softbiz Dating Script 1.0
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d) index.php, and (e) news_desc.php.
network
low complexity
softbiz
7.5
2006-04-07 CVE-2006-1660 Cross-Site Scripting vulnerability in Image Gallery
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter.
network
softbiz
6.8
2006-04-07 CVE-2006-1659 SQL Injection vulnerability in Softbiz Image Gallery
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.
network
low complexity
softbiz
6.4