VendorsPHP Script Toolspsy_auctionany version
Vulnerabilities

PHP Script Tools Psy Auction any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-7005
SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2007-02-12 · Modified
7.51 PoCEPSS 0.010
CVE-2006-7004
Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2007-02-12 · Modified
6.81 PoCEPSS 0.018