彙總 softbizscripts 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 SQL 注入與跨站腳本 等問題,部分漏洞可能導致 資料外洩,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2010-4905 | SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter. | [email protected] | 7.5 | 0.12% | 2011-10-08 | 2026-04-29 |
| CVE-2010-0758 | SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.14% | 2010-02-27 | 2026-04-29 |
| CVE-2009-2790 | SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4. | [email protected] | 7.5 | 0.13% | 2009-08-17 | 2026-04-06 |
| CVE-2009-2232 | SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | [email protected] | 7.5 | 0.42% | 2009-06-26 | 2026-04-23 |
| CVE-2008-6325 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php, (5) radio parameter to showcategory.php, (6) msg parameter to admin/adminhome.php, and (7) msg parameter to admin/index.php. NOTE: a different signinform.php file is already covered | [email protected] | 4.3 | 0.39% | 2009-02-27 | 2026-04-23 |
| CVE-2008-6306 | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | [email protected] | 4.3 | 0.26% | 2009-02-26 | 2026-04-23 |
| CVE-2008-3511 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image | [email protected] | 4.3 | 0.16% | 2008-08-07 | 2026-04-06 |
| CVE-2008-2874 | SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050. | [email protected] | 7.5 | 0.47% | 2008-06-26 | 2026-04-23 |
| CVE-2008-2087 | SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817. | [email protected] | 6.8 | 1.17% | 2008-05-06 | 2026-04-06 |
| CVE-2008-1050 | SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | [email protected] | 7.5 | 0.27% | 2008-02-27 | 2026-04-06 |
| CVE-2007-6125 | SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter. | [email protected] | 7.5 | 0.70% | 2007-11-26 | 2026-04-06 |
| CVE-2007-6124 | Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. | [email protected] | 4.3 | 4.74% | 2007-11-26 | 2026-04-06 |
| CVE-2007-5999 | SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.46% | 2007-11-15 | 2026-04-23 |
| CVE-2007-5998 | SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter. | [email protected] | 6.5 | 0.39% | 2007-11-15 | 2026-04-23 |
| CVE-2007-5997 | SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | [email protected] | 6.5 | 0.39% | 2007-11-15 | 2026-04-23 |
| CVE-2007-5996 | SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449. | [email protected] | 7.5 | 0.46% | 2007-11-15 | 2026-04-23 |
| CVE-2007-5449 | SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | [email protected] | 7.5 | 0.73% | 2007-10-14 | 2026-04-06 |
| CVE-2007-5316 | SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | [email protected] | 5.0 | 1.08% | 2007-10-09 | 2026-04-23 |
| CVE-2007-5122 | SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.60% | 2007-09-27 | 2026-04-23 |
| CVE-2006-3607 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php. | [email protected] | 4.3 | 0.44% | 2006-07-18 | 2026-04-06 |