Security Vulnerabilities
- CVEs Published In October 2017
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
CPA Lead Reward Script allows SQL Injection via the username parameter.
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.