VendorsScriptsfrenzye-uploader_proall versions
Vulnerabilities

Scriptsfrenzy E-uploader Pro

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2008-5075
Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php.
Published 2008-11-14 · Modified
6.81 PoCEPSS 0.009