Vulnerabilities (CVE)

Filtered by vendor Creascripts Subscribe
Filtered by product Creadirectory
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6082 1 Creascripts 1 Creadirectory 2024-02-14 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
CVE-2006-6083 1 Creascripts 1 Creadirectory 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.
CVE-2007-2342 1 Creascripts 1 Creadirectory 2017-10-11 7.5 HIGH N/A
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.