| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-17607 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | |
| CVE-2017-17606 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17605 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. | |
| CVE-2017-17604 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. | |
| CVE-2017-17603 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | |
| CVE-2017-17602 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. | |
| CVE-2017-17601 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. | |
| CVE-2017-17600 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | |
| CVE-2017-17599 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. | |
| CVE-2017-17598 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. | |
| CVE-2017-17597 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. | |
| CVE-2017-17596 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter. | |
| CVE-2017-17595 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | |
| CVE-2017-17594 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. | |
| CVE-2017-17592 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. | |
| CVE-2017-17591 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | |
| CVE-2017-17590 | Cri | 0.67 | 9.8 | 0.01 | Dec 13, 2017 | FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. | |
| CVE-2017-17589 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. | |
| CVE-2017-17588 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. | |
| CVE-2017-17587 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. | |
| CVE-2017-17586 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. | |
| CVE-2017-17585 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. | |
| CVE-2017-17584 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | |
| CVE-2017-17583 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | |
| CVE-2017-17582 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | |
| CVE-2017-17581 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | |
| CVE-2017-17580 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | |
| CVE-2017-17579 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | |
| CVE-2017-17578 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | |
| CVE-2017-17577 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | |
| CVE-2017-17576 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter. | |
| CVE-2017-17575 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. | |
| CVE-2017-17574 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. | |
| CVE-2017-17573 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | |
| CVE-2017-17572 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | |
| CVE-2017-17571 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | |
| CVE-2017-17570 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | |
| CVE-2017-16935 | Cri | 0.67 | 9.8 | 0.07 | Nov 24, 2017 | Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request. | |
| CVE-2015-3934 | Cri | 0.67 | 9.8 | 0.01 | Nov 21, 2017 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login. | |
| CVE-2017-16783 | Cri | 0.67 | 9.8 | 0.10 | Nov 10, 2017 | In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | |
| CVE-2017-16780 | Cri | 0.67 | 9.8 | 0.02 | Nov 10, 2017 | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | |
| CVE-2017-11309 | Cri | 0.67 | 9.6 | 0.25 | Nov 10, 2017 | Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response. | |
| CVE-2015-3933 | Cri | 0.67 | 9.8 | 0.02 | Nov 8, 2017 | Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php. | |
| CVE-2017-16543 | Cri | 0.67 | 9.8 | 0.02 | Nov 5, 2017 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. | |
| CVE-2017-15993 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | |
| CVE-2017-15992 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. | |
| CVE-2017-15991 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982. | |
| CVE-2017-15990 | Cri | 0.67 | 9.8 | 0.09 | Oct 31, 2017 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | |
| CVE-2017-15989 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. | |
| CVE-2017-15988 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. |
- risk 0.67cvss 9.8epss 0.03
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
- risk 0.67cvss 9.8epss 0.03
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
- risk 0.67cvss 9.8epss 0.03
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
- risk 0.67cvss 9.8epss 0.03
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.
- risk 0.67cvss 9.8epss 0.03
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
- risk 0.67cvss 9.8epss 0.03
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
- risk 0.67cvss 9.8epss 0.03
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
- risk 0.67cvss 9.8epss 0.03
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
- risk 0.67cvss 9.8epss 0.03
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
- risk 0.67cvss 9.8epss 0.01
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
- risk 0.67cvss 9.8epss 0.02
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.
- risk 0.67cvss 9.8epss 0.02
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.
- risk 0.67cvss 9.8epss 0.02
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
- risk 0.67cvss 9.8epss 0.02
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
- risk 0.67cvss 9.8epss 0.02
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
- risk 0.67cvss 9.8epss 0.02
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
- risk 0.67cvss 9.8epss 0.02
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
- risk 0.67cvss 9.8epss 0.02
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
- risk 0.67cvss 9.8epss 0.02
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
- risk 0.67cvss 9.8epss 0.02
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
- risk 0.67cvss 9.8epss 0.03
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
- risk 0.67cvss 9.8epss 0.02
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
- risk 0.67cvss 9.8epss 0.02
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
- risk 0.67cvss 9.8epss 0.02
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
- risk 0.67cvss 9.8epss 0.07
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.
- risk 0.67cvss 9.8epss 0.01
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
- risk 0.67cvss 9.8epss 0.10
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
- risk 0.67cvss 9.8epss 0.02
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
- risk 0.67cvss 9.6epss 0.25
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
- risk 0.67cvss 9.8epss 0.02
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
- risk 0.67cvss 9.8epss 0.02
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
- risk 0.67cvss 9.8epss 0.01
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
- risk 0.67cvss 9.8epss 0.01
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
- risk 0.67cvss 9.8epss 0.01
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.
- risk 0.67cvss 9.8epss 0.09
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
- risk 0.67cvss 9.8epss 0.01
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
- risk 0.67cvss 9.8epss 0.01
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.