Vulnerabilities > Turnkeyforms > Local Classifieds

DATE CVE VULNERABILITY TITLE RISK
2009-03-02 CVE-2008-6351 Cross-Site Scripting vulnerability in Turnkeyforms Local Classifieds
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.
4.3
2009-03-02 CVE-2008-6350 SQL Injection vulnerability in Turnkeyforms Local Classifieds
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.
network
low complexity
turnkeyforms CWE-89
7.5
2009-02-26 CVE-2008-6302 Permissions, Privileges, and Access Controls vulnerability in Turnkeyforms Local Classifieds
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.
network
low complexity
turnkeyforms CWE-264
7.5