Indexcor / Ezdatabase
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-0592 | Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to… | MEDIUM | 6.8 | Jan 30, 2007 |
| CVE-2006-0315 | index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers… | MEDIUM | 5.8 | Jan 19, 2006 |
| CVE-2006-0214 | Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php,… | HIGH | 7.5 | Jan 15, 2006 |
| CVE-2005-4304 | index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathnam… | MEDIUM | 5.0 | Dec 17, 2005 |
| CVE-2005-4303 | SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter. | HIGH | 7.5 | Dec 17, 2005 |
| CVE-2005-4302 | Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in t… | MEDIUM | 5.0 | Dec 17, 2005 |
Showing 1 to 6 of 6 CVEs