VYPR

Ebay Clone

by Ebayclonescript

CVEs (5)

  • CVE-2017-17573CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.

  • CVE-2009-3712Oct 16, 2009
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.

  • CVE-2009-2894Aug 20, 2009
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.

  • CVE-2009-2424Jul 10, 2009
    risk 0.03cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

  • CVE-2009-2423Jul 10, 2009
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.