RSS   Vulnerabilities for 'Faname'   RSS

2008-01-17
 
CVE-2008-0328

 

 
SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

 
2008-07-08
 
CVE-2007-3653

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.

 
 
CVE-2007-3652

CWE-89
 

 
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.

 
 
CVE-2007-3651

CWE-200
 

 
class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message.

 

 >>> Vendor: Fascript 6 Products
Faname
Fapersian petition
Fapersianhack
Famp3
Faphoto
Faupload


Copyright 2024, cxsecurity.com

 

Back to Top