CVE-2007-3354
- EPSS 0.7%
- Veröffentlicht 22.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php...
CVE-2007-3355
- EPSS 0.41%
- Veröffentlicht 22.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in NetClassifieds Premium Edition allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2007-3356
- EPSS 0.74%
- Veröffentlicht 22.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of...
- EPSS 0.21%
- Veröffentlicht 22.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
NetClassifieds Premium Edition does not use encryption for (1) stored passwords or (2) sensitive data, which might allow attackers to obtain information via certain vectors.
CVE-2005-3978
- EPSS 0.99%
- Veröffentlicht 03.12.2005 19:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) V...