|
251301
|
9.8 |
CRITICAL
Network
|
gigs_script_project
|
gigs_script
|
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17576
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251302
|
9.8 |
CRITICAL
Network
|
groupon_clone_project
|
groupon_clone
|
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17575
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251303
|
9.8 |
CRITICAL
Network
|
care_clone_project
|
care_clone
|
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17574
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251304
|
9.8 |
CRITICAL
Network
|
fortunescripts
|
ebay_clone
|
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17573
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251305
|
9.8 |
CRITICAL
Network
|
amazon_clone_project
|
amazon_clone
|
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
|
CWE-89
SQL Injection
|
CVE-2017-17572
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251306
|
9.8 |
CRITICAL
Network
|
foodpanda_clone_project
|
foodpanda_clone
|
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17571
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251307
|
9.8 |
CRITICAL
Network
|
expedia_clone_project
|
expedia_clone
|
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17570
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251308
|
6.1 |
MEDIUM
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17569
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251309
|
7.5 |
HIGH
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive inform…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-17568
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251310
|
7.5 |
HIGH
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17567
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|