Smartisoft

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-2315

    PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.

    Last Modified: Apr 11, 2025
    Published: Jun 17, 2010

    CVE-2009-4221

    SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.

    Last Modified: Apr 23, 2026
    Published: Dec 07, 2009

    CVE-2009-4222

    phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a direct request.

    Last Modified: Apr 23, 2026
    Published: Dec 07, 2009

    CVE-2008-3767

    SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Last Modified: Apr 23, 2026
    Published: Aug 22, 2008

    CVE-2006-2527

    Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.

    Last Modified: Apr 16, 2026
    Published: May 22, 2006
    Items Per Page