-
CVE-2017-17610
•
published on December 13, 2017
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
-
CVE-2017-17611
•
published on December 13, 2017
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17619
•
published on December 13, 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17620
•
published on December 13, 2017
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
-
CVE-2017-17621
•
published on December 13, 2017
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
-
CVE-2017-17628
•
published on December 13, 2017
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
-
CVE-2017-17630
•
published on December 13, 2017
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17602
•
published on December 13, 2017
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
-
CVE-2017-17608
•
published on December 13, 2017
Child Care Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17614
•
published on December 13, 2017
Food Order Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17623
•
published on December 13, 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
-
CVE-2017-17624
•
published on December 13, 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
-
CVE-2017-17625
•
published on December 13, 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
-
CVE-2017-17570
•
published on December 13, 2017
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
-
CVE-2017-17572
•
published on December 13, 2017
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
-
CVE-2017-17579
•
published on December 13, 2017
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
-
CVE-2017-17584
•
published on December 13, 2017
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
-
CVE-2017-17588
•
published on December 13, 2017
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.
-
CVE-2017-17593
•
published on December 13, 2017
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
-
CVE-2017-17599
•
published on December 13, 2017
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.