Indexcor

Ezdatabase

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.63%
  • Veröffentlicht 30.01.2007 18:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database.

Exploit
  • EPSS 1.66%
  • Veröffentlicht 19.01.2006 01:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) ...

  • EPSS 2.79%
  • Veröffentlicht 15.01.2006 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.

Exploit
  • EPSS 3.88%
  • Veröffentlicht 17.12.2005 00:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.

  • EPSS 0.35%
  • Veröffentlicht 17.12.2005 00:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 17.12.2005 00:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has t...