-
CVE-2017-17603
•
published on December 13, 2017
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
-
CVE-2017-17605
•
published on December 13, 2017
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
-
CVE-2017-17606
•
published on December 13, 2017
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
-
CVE-2017-17613
•
published on December 13, 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
-
CVE-2017-17616
•
published on December 13, 2017
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
-
CVE-2017-17622
•
published on December 13, 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
-
CVE-2017-17638
•
published on December 13, 2017
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
-
CVE-2017-17631
•
published on December 13, 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
-
CVE-2017-17633
•
published on December 13, 2017
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
-
CVE-2017-17636
•
published on December 13, 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
-
CVE-2017-17640
•
published on December 13, 2017
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
-
CVE-2017-17641
•
published on December 13, 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
-
CVE-2017-17637
•
published on December 13, 2017
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
-
CVE-2017-17639
•
published on December 13, 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
-
CVE-2017-17642
•
published on December 13, 2017
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
-
CVE-2017-17632
•
published on December 13, 2017
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
-
CVE-2017-17634
•
published on December 13, 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
-
CVE-2017-17635
•
published on December 13, 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
-
CVE-2017-4942
•
published on December 13, 2017
VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administrator.
-
CVE-2017-5530
•
published on December 13, 2017
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.