RSS   Vulnerabilities for 'Locazolist classifieds'   RSS

2007-01-09
 
CVE-2007-0129

 

 
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.

 
2006-06-06
 
CVE-2006-2858

CWE-Other
 

 
SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

 
2005-12-13
 
CVE-2005-4205

 

 
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.

 

 >>> Vendor: Locazo 2 Products
Locazolist
Locazolist classifieds


Copyright 2024, cxsecurity.com

 

Back to Top