Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dynpg dynpg vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote malicious users to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are o...
Dynpg Dynpg 4.2.0
Dynpg Dynpg 4.1.1
1 EDB exploit
5.1
CVSSv2
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.ph...
Dynpg Dynpg
2 EDB exploits
3.5
CVSSv2
CVE-2021-27529
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "limit" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27531
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "query" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2020-27406
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated malicious users to execute arbitrary code via the groupname.
Dynpg Dynpg 4.9.1
3.5
CVSSv2
CVE-2021-27526
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "page" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27528
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "refID" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27530
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote malicious user to inject javascript via URI in /index.php.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27527
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "valueID" parameter.
Dynpg Dynpg 4.9.2
7.5
CVSSv2
CVE-2010-4400
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote malicious users to execute arbitrary SQL commands via the giveRights_UserId parameter.
Dynpg Dynpg 4.2.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »