Security Vulnerabilities
- CVEs Published In December 2017
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.