Security Vulnerabilities
- CVEs Published In December 2017
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
Child Care Script 1.0 has SQL Injection via the /list city parameter.
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.