CVE Browser

More filters (active)
CVE-2012-0983 HIGH

SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.…

CVSS 7.5 EPSS 1.04% Feb 2, 2012
CVE-2009-4826 MEDIUM

Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of…

CVSS 6.8 EPSS 0.94% Apr 27, 2010
CVE-2009-4683 HIGH

Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal seq…

CVSS 7.5 EPSS 2.36% Mar 10, 2010
CVE-2009-4682 MEDIUM

Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a…

CVSS 4.3 EPSS 1.44% Mar 10, 2010
CVE-2009-4385 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authentication of arb…

CVSS 6.8 EPSS 0.97% Dec 22, 2009
CVE-2009-4384 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 EPSS 1.48% Dec 22, 2009
CVE-2009-4366 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the yr parame…

CVSS 4.3 EPSS 1.52% Dec 21, 2009
CVE-2009-4365 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of adminis…

CVSS 4.3 EPSS 0.92% Dec 21, 2009
CVE-2009-4364 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML via the cname paramet…

CVSS 4.3 EPSS 1.47% Dec 21, 2009
CVE-2009-4317 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML via the sid parameter…

CVSS 4.3 EPSS 1.10% Dec 14, 2009
CVE-2009-3601 MEDIUM

Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr…

CVSS 4.3 EPSS 3.03% Oct 8, 2009
CVE-2009-2551 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id…

CVSS 4.3 EPSS 1.53% Jul 20, 2009
CVE-2009-0762 MEDIUM

Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOT…

CVSS 4.3 EPSS 1.02% Mar 3, 2009
CVE-2008-6112 MEDIUM

Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a…

CVSS 5.0 EPSS 3.02% Feb 11, 2009
CVE-2008-6090 MEDIUM

Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in th…

CVSS 4.3 EPSS 2.29% Feb 6, 2009
CVE-2008-6089 MEDIUM

Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id p…

CVSS 5.0 EPSS 3.11% Feb 6, 2009
CVE-2008-5218 MEDIUM

ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.

CVSS 5.0 EPSS 2.70% Nov 25, 2008
CVE-2008-2116 MEDIUM

Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot…

CVSS 4.4 EPSS 2.54% May 8, 2008
CVE-2008-2115 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 EPSS 1.49% May 8, 2008
CVE-2007-0518 HIGH

Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers…

CVSS 7.5 EPSS 2.49% Jan 26, 2007
CVE-2007-0517 HIGH

Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwo…

CVSS 7.5 EPSS 1.47% Jan 26, 2007
CVE-2006-3004 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id paramet…

CVSS 4.3 EPSS 2.05% Jun 13, 2006
CVE-2006-2232 MEDIUM

Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments f…

CVSS 4.3 EPSS 1.23% May 5, 2006

Showing 1 to 23 CVEs · page 1