Vulnerabilities > Softbiz > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-08-07 | CVE-2008-3511 | Cross-Site Scripting vulnerability in Softbiz Image Gallery Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. | 4.3 |
2008-05-06 | CVE-2008-2087 | SQL Injection vulnerability in Softbiz web Hosting Directory Script SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817. | 6.8 |
2007-11-26 | CVE-2007-6124 | Cross-Site Scripting vulnerability in Softbiz Freelancers Script 1.0 Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. | 4.3 |
2006-04-07 | CVE-2006-1660 | Cross-Site Scripting vulnerability in Image Gallery Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. network softbiz | 6.8 |
2006-04-07 | CVE-2006-1659 | SQL Injection vulnerability in Softbiz Image Gallery Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php. | 6.4 |