Vulnerabilities (CVE)

Filtered by vendor Preprojects Subscribe
Total 29 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6052 1 Preprojects 1 Pre E-learning Portal 2024-02-04 5.0 MEDIUM N/A
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
CVE-2008-6888 1 Preprojects 1 Pre Classified Listings 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.
CVE-2008-6055 1 Preprojects 1 Pre Classified Listings 2024-02-04 5.0 MEDIUM N/A
PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
CVE-2008-6798 1 Preprojects 1 Pre Real Estate Listings 2024-02-04 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
CVE-2008-2114 1 Preprojects 1 Pre Shopping Mall 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
CVE-2008-5976 1 Preprojects 1 Php Jobwebsite Pro 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.
CVE-2008-5977 1 Preprojects 1 Php Jobwebsite Pro 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.
CVE-2008-2915 1 Preprojects 1 Pre Job Board 2024-02-04 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw parameter.
CVE-2008-6887 1 Preprojects 1 Pre Classified Listings 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.