Skip to main content

Vendor archive

turnkeyforms CVEs

Beta · best-effort

12 CVEs tagged to vendor turnkeyforms0 Critical, 9 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2009-4858

Published May 11, 2010

Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6963

Published Aug 13, 2009

admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6941

Published Aug 12, 2009

SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6940

Published Aug 12, 2009

TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6939

Published Aug 12, 2009

TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6723

Published Apr 14, 2009

TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6351

Published Mar 2, 2009

Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6350

Published Mar 2, 2009

SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6349

Published Mar 2, 2009

SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6302

Published Feb 26, 2009

TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5487

Published Dec 12, 2008

Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5486

Published Dec 12, 2008

SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1