|
252491
|
9.8 |
CRITICAL
Network
|
readymadeb2bscript
|
basic_b2b_script
|
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15985
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252492
|
9.8 |
CRITICAL
Network
|
bekirk
|
creative_management_system_lite
|
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2017-15984
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252493
|
9.8 |
CRITICAL
Network
|
geniusocean
|
mymagazine_magazine_\&_blog_cms
|
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
|
CWE-89
SQL Injection
|
CVE-2017-15983
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252494
|
9.8 |
CRITICAL
Network
|
geniusocean
|
news
|
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
|
CWE-89
SQL Injection
|
CVE-2017-15982
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252495
|
9.8 |
CRITICAL
Network
|
geniusocean
|
newspaper
|
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
|
CWE-89
SQL Injection
|
CVE-2017-15981
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252496
|
9.8 |
CRITICAL
Network
|
rowindex
|
us_zip_codes_database_script
|
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15980
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252497
|
9.8 |
CRITICAL
Network
|
odallated
|
shareet
|
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15979
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252498
|
9.8 |
CRITICAL
Network
|
arox
|
school_erp_php_script
|
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15978
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252499
|
9.8 |
CRITICAL
Network
|
protectedlinks
|
expiring_download_links
|
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15977
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252500
|
5.4 |
MEDIUM
Network
|
synology
|
audio_station
|
Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15888
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|