Vulnerabilities (CVE)

Filtered by vendor All Enthusiast Inc Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4864 1 All Enthusiast Inc 1 Reviewpost Php Pro 2024-02-14 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in All Enthusiast ReviewPost 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the RP_PATH parameter.
CVE-2004-2175 1 All Enthusiast Inc 1 Reviewpost Php Pro 2024-02-04 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php.