Vendor CVEs
FS
All CVEs
23 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17643 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | ||
| CVE-2017-17590 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. | ||
| CVE-2017-17589 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. | ||
| CVE-2017-17587 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. | ||
| CVE-2017-17586 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. | ||
| CVE-2017-17584 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | ||
| CVE-2017-17583 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | ||
| CVE-2017-17582 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | ||
| CVE-2017-17581 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | ||
| CVE-2017-17580 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | ||
| CVE-2017-17579 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | ||
| CVE-2017-17578 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | ||
| CVE-2017-17577 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | ||
| CVE-2017-17573 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | ||
| CVE-2017-17572 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | ||
| CVE-2017-17571 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | ||
| CVE-2017-17570 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | ||
| CVE-2023-30350 | Hig | 0.61 | 8.8 | 0.05 | May 29, 2023 | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | ||
| CVE-2020-24033 | Hig | 0.57 | 8.8 | 0.01 | Oct 22, 2020 | An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating… | ||
| CVE-2017-17903 | Hig | 0.57 | 8.8 | 0.00 | Dec 27, 2017 | FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | ||
| CVE-2025-25613 | Hig | 0.49 | 7.5 | 0.00 | Nov 20, 2025 | FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were… | ||
| CVE-2025-25625 | Med | 0.35 | 5.4 | 0.00 | Mar 13, 2025 | A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML… | ||
| CVE-2017-17904 | Med | 0.35 | 5.4 | 0.00 | Dec 27, 2017 | FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile. |
- risk 0.67cvss 9.8epss 0.03
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
- risk 0.67cvss 9.8epss 0.04
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.
- risk 0.67cvss 9.8epss 0.03
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.
- risk 0.67cvss 9.8epss 0.03
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
- risk 0.67cvss 9.8epss 0.03
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
- risk 0.67cvss 9.8epss 0.03
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
- risk 0.67cvss 9.8epss 0.03
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
- risk 0.67cvss 9.8epss 0.03
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
- risk 0.67cvss 9.8epss 0.03
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
- risk 0.61cvss 8.8epss 0.05
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating…
- risk 0.57cvss 8.8epss 0.00
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
- risk 0.49cvss 7.5epss 0.00
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML…
- risk 0.35cvss 5.4epss 0.00
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.