← Back

Orbitscripts

orbitscripts

4 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Smartppc Pro
smartppc_pro
Orbithyip
orbithyip
Smartppc
smartppc

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Orbitscripts
1Orbit Open Ad Server
May 6, 2026
Apr 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.
1Orbitscripts
2Smartppc
Smartppc Pro
Apr 23, 2026
Jul 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter.
1Orbitscripts
1Orbithyip
Apr 16, 2026
May 2, 2006
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
1Orbitscripts
1Smartppc Pro
Apr 16, 2026
Nov 26, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and (3) search.php.