Skip to main content

Vendor archive

preprojects CVEs

Beta · best-effort

29 CVEs tagged to vendor preprojects0 Critical, 20 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2012-5334

Published Oct 8, 2012

SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5333

Published Oct 8, 2012

SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5139

Published Aug 31, 2012

SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4776

Published Mar 23, 2011

SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1371

Published Apr 13, 2010

Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0954

Published Mar 10, 2010

SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7052

Published Aug 24, 2009

Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6888

Published Aug 3, 2009

Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6887

Published Aug 3, 2009

SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6798

Published May 7, 2009

Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6796

Published May 7, 2009

SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (ak…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6716

Published Apr 13, 2009

homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6715

Published Apr 13, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) ho…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6232

Published Feb 20, 2009

Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6231

Published Feb 20, 2009

Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6230

Published Feb 20, 2009

SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6055

Published Feb 4, 2009

PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6053

Published Feb 4, 2009

PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct reques…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6052

Published Feb 4, 2009

PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5977

Published Jan 27, 2009

SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5976

Published Jan 27, 2009

Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2914

Published Jun 30, 2008

SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2