VendorsCityforfreeindexcity1.0
Vulnerabilities

Cityforfree Indexcity 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-4323
SQL injection vulnerability in list.php in CityForFree indexcity 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
Published 2006-08-24 · Modified
7.5EPSS 0.014
CVE-2006-4324
Cross-site scripting (XSS) vulnerability in add_url2.php in CityForFree indexcity 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Published 2006-08-24 · Modified
6.8EPSS 0.016