VendorsPhpoutsourcingnoahs_classifiedsall versions
Vulnerabilities

Phpoutsourcing Noahs Classifieds

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2006-0881
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.
Published 2006-02-24 · Modified
7.51 PoCEPSS 0.077
CVE-2006-0879
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
Published 2006-02-24 · Modified
7.51 PoCEPSS 0.013
CVE-2005-2979
SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.
Published 2005-09-19 · Modified
7.51 PoCEPSS 0.012
CVE-2006-1331
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.
Published 2006-03-21 · Modified
6.8EPSS 0.014
CVE-2006-5293
Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter.
Published 2006-10-16 · Modified
6.8EPSS 0.013
CVE-2006-1332
Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message.
Published 2006-03-21 · Modified
6.4EPSS 0.016
CVE-2006-0882
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.
Published 2006-02-24 · Modified
5.01 PoCEPSS 0.028
CVE-2006-0878
Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php.
Published 2006-02-24 · Modified
5.0EPSS 0.015
CVE-2006-0880
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.
Published 2006-02-24 · Modified
4.31 PoCEPSS 0.019
CVE-2005-2980
Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.
Published 2005-09-19 · Modified
4.31 PoCEPSS 0.018