Skip to main content

Vendor archive

china-on-site CVEs

Beta · best-effort

9 CVEs tagged to vendor china-on-site2 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2008-6761

Published Apr 28, 2009

Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname p…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6750

Published Apr 24, 2009

Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6749

Published Apr 24, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL command…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6731

Published Apr 20, 2009

Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable exte…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6730

Published Apr 20, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6241

Published Feb 23, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6142

Published Feb 16, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5927

Published Jan 21, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka us…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1237

Published May 2, 2005

SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1