← Back

Softbizscripts

softbizscripts

27 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Dating Script
dating_script
Faq Script
faq_script

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Softbizscripts
1Article Directory Script
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.
1Softbizscripts
1Softbiz Jobs And Recruitment Script
Apr 29, 2026
Feb 27, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter.
2Softbiz
Softbizscripts
2Dating Script
Dating Script
Apr 6, 2026
Aug 17, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.
1Softbizscripts
1Banner Ad Management Script
Apr 23, 2026
Jun 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; t...Show more
SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Softbizscripts
1Classifieds Script
Apr 23, 2026
Feb 27, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advert...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php, (5) radio parameter to showcategory.php, (6) msg parameter to admin/adminhome.php, and (7) msg parameter to admin/index.php. NOTE: a different signinform.php file is already covered by CVE-2008-6306.Show less
1Softbizscripts
1Classifieds Script
Apr 23, 2026
Feb 26, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is...Show more
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
2Softbiz
Softbizscripts
2Image Gallery
Image Gallery Script
Apr 6, 2026
Aug 7, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Softbizscripts
1Softbiz Jokes And Funny Pics Script
Apr 23, 2026
Jun 26, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.
2Softbiz
Softbizscripts
2Web Hosting Directory Script
Web Hosting Directory Script
Apr 6, 2026
May 6, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different v...Show more
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.Show less
2Softbiz
Softbizscripts
2Jokes And Funny Pictures Script
Jokes And Funny Pictures Script
Apr 6, 2026
Feb 27, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
2Softbiz
Softbizscripts
2Freelancers Script
Freelancers Script
Apr 6, 2026
Nov 26, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
2Softbiz
Softbizscripts
2Freelancers Script
Freelancers Script
Apr 6, 2026
Nov 26, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.
1Softbizscripts
1Softbiz Auctions Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Softbizscripts
1Ad Management Plus Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.
1Softbizscripts
1Banner Exchange Network Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
1Softbizscripts
1Link Directory Script
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.
2Softbiz
Softbizscripts
2Recipes Portal Script
Recipes Portal Script
Apr 6, 2026
Oct 14, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
1Softbizscripts
1Softbiz Jobs And Recruitment Script
Apr 23, 2026
Oct 9, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Softbizscripts
1Classifieds Plus Script
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.
2Softbiz
Softbizscripts
2Banner Exchange
Banner Exchange Script
Apr 6, 2026
Jul 18, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.Show less