Vulnerabilities > Softbizscripts > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-02-27 | CVE-2008-6325 | Cross-Site Scripting vulnerability in Softbizscripts Classifieds Script Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php, (5) radio parameter to showcategory.php, (6) msg parameter to admin/adminhome.php, and (7) msg parameter to admin/index.php. | 4.3 |
2009-02-26 | CVE-2008-6306 | Cross-Site Scripting vulnerability in Softbizscripts Classifieds Script Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | 4.3 |
2007-11-15 | CVE-2007-5998 | SQL Injection vulnerability in Softbizscripts AD Management Plus Script 1.0 SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter. | 6.5 |
2007-11-15 | CVE-2007-5997 | SQL Injection vulnerability in Softbizscripts Banner Exchange Network Script 1.0 SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | 6.5 |
2007-10-09 | CVE-2007-5316 | SQL Injection vulnerability in Softbizscripts Softbiz Jobs and Recruitment Script SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 5.0 |