VYPR

Locazolist Classifieds

by Locazo

CVEs (3)

  • CVE-2007-0129Jan 9, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.

  • CVE-2006-2858Jun 6, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

  • CVE-2005-4205Dec 13, 2005
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.