Vulnerabilities (CVE)

Filtered by vendor Discountedscripts Subscribe
Filtered by product Acg Ptp
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3944 1 Discountedscripts 1 Acg Ptp 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.
CVE-2008-3782 1 Discountedscripts 1 Acg Ptp 2024-02-04 3.5 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ Entry.