Vulnerabilities > Softbizscripts > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-02-27 CVE-2008-6325 Cross-Site Scripting vulnerability in Softbizscripts Classifieds Script
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php, (5) radio parameter to showcategory.php, (6) msg parameter to admin/adminhome.php, and (7) msg parameter to admin/index.php.
4.3
2009-02-26 CVE-2008-6306 Cross-Site Scripting vulnerability in Softbizscripts Classifieds Script
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
4.3
2007-11-15 CVE-2007-5998 SQL Injection vulnerability in Softbizscripts AD Management Plus Script 1.0
SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.
network
low complexity
softbizscripts CWE-89
6.5
2007-11-15 CVE-2007-5997 SQL Injection vulnerability in Softbizscripts Banner Exchange Network Script 1.0
SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
network
low complexity
softbizscripts CWE-89
6.5
2007-10-09 CVE-2007-5316 SQL Injection vulnerability in Softbizscripts Softbiz Jobs and Recruitment Script
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
network
low complexity
softbizscripts CWE-89
5.0