-
CVE-2017-17610
•
published on December 13, 2017
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
-
CVE-2017-17611
•
published on December 13, 2017
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17615
•
published on December 13, 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
-
CVE-2017-17624
•
published on December 13, 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
-
CVE-2017-17625
•
published on December 13, 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
-
CVE-2017-17626
•
published on December 13, 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
-
CVE-2017-17631
•
published on December 13, 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
-
CVE-2017-17634
•
published on December 13, 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
-
CVE-2017-17637
•
published on December 13, 2017
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
-
CVE-2017-17639
•
published on December 13, 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
-
CVE-2017-17538
•
published on December 13, 2017
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
-
CVE-2017-17567
•
published on December 13, 2017
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
-
CVE-2017-17568
•
published on December 13, 2017
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request.
-
CVE-2017-17569
•
published on December 13, 2017
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
-
CVE-2017-17570
•
published on December 13, 2017
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
-
CVE-2017-17571
•
published on December 13, 2017
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
-
CVE-2017-17572
•
published on December 13, 2017
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
-
CVE-2017-17573
•
published on December 13, 2017
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
-
CVE-2017-17574
•
published on December 13, 2017
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
-
CVE-2017-17575
•
published on December 13, 2017
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.