|
252831
|
9.8 |
CRITICAL
Network
|
softdatepro
|
same_date_pro
|
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
|
CWE-89
SQL Injection
|
CVE-2017-15971
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252832
|
9.8 |
CRITICAL
Network
|
phpcityportal
|
phpcityportal
|
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15970
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252833
|
9.8 |
CRITICAL
Network
|
pilotgroup
|
allsharevideo
|
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
|
CWE-89
SQL Injection
|
CVE-2017-15969
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252834
|
9.8 |
CRITICAL
Network
|
contractorscripts
|
mybuildersite
|
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15968
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252835
|
9.8 |
CRITICAL
Network
|
mailing-manager
|
mailing_list_manager_pro
|
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
|
CWE-89
SQL Injection
|
CVE-2017-15967
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252836
|
9.8 |
CRITICAL
Network
|
zh_yandexmap_project
|
zh_yandexmap
|
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2017-15966
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252837
|
9.8 |
CRITICAL
Network
|
nswd
|
ns_download_shop
|
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.
|
CWE-89
SQL Injection
|
CVE-2017-15965
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252838
|
9.8 |
CRITICAL
Network
|
nicephpscripts
|
job_board_script
|
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
|
CWE-89
SQL Injection
|
CVE-2017-15964
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252839
|
9.8 |
CRITICAL
Network
|
itechscripts
|
gigs_script
|
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15963
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252840
|
9.8 |
CRITICAL
Network
|
istock_management_system_project
|
istock_management_system
|
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15962
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|