CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2008-6526 HIGH

SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a differe…

CVSS 7.5 EPSS 0.97% Mar 25, 2009
CVE-2008-4703 HIGH

SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.

CVSS 7.5 EPSS 0.97% Oct 23, 2008
CVE-2008-1838 HIGH

SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to inde…

CVSS 7.5 EPSS 0.97% Apr 16, 2008
CVE-2008-1224 MEDIUM

Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 EPSS 1.02% Mar 10, 2008
CVE-2008-1211 MEDIUM

Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in c…

CVSS 4.3 EPSS 1.02% Mar 8, 2008
CVE-2007-5835 MEDIUM

Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which all…

CVSS 5.0 EPSS 1.20% Nov 5, 2007
CVE-2007-5834 MEDIUM

Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.

CVSS 4.3 EPSS 1.02% Nov 5, 2007
CVE-2007-5833 LOW

Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web scri…

CVSS 3.5 EPSS 0.69% Nov 5, 2007
CVE-2006-3957 HIGH

PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parame…

CVSS 7.5 EPSS 2.52% Aug 1, 2006
CVE-2006-3527 HIGH

Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPa…

CVSS 7.5 EPSS 4.27% Jul 12, 2006
CVE-2005-3911 HIGH

Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year an…

CVSS 7.5 EPSS 1.16% Nov 30, 2005
CVE-2004-0275 MEDIUM

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via th…

CVSS 5.0 EPSS 2.61% Mar 18, 2004

Showing 1 to 12 CVEs · page 1