RSS   Vulnerabilities for 'Dating agent pro'   RSS

2006-06-28
 
CVE-2006-3284

CWE-Other
 

 
Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in (1) webmaster/index.php and (2) search.php.

 
 
CVE-2006-3283

CWE-Other
 

 
SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.

 
 
CVE-2006-3282

CWE-Other
 

 
requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

 

 >>> Vendor: Datetopia 3 Products
Dating agent pro
Buy dating site
Match agency biz


Copyright 2024, cxsecurity.com

 

Back to Top