VYPR

Web Hosting Directory Script

Sign in to watch

by Softbizscripts

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2008-20870.030.01May 6, 2008SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
CVE-2005-38170.030.01Nov 26, 2005Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.