Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webspell webspell 4.0 vulnerabilities and exploits
(subscribe to this query)
545
VMScore
CVE-2006-4782
src/index.php in WebSPELL 4.01.01 and previous versions, when register_globals is enabled, allows remote malicious users to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.
Webspell Webspell 4.0
Webspell Webspell
Webspell Webspell 4.1
Webspell Webspell 4.1.1
1 EDB exploit
755
VMScore
CVE-2007-1163
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
Webspell Webspell
Webspell Webspell 4.0
Webspell Webspell 4.01.00
Webspell Webspell 4.01.01
1 EDB exploit
454
VMScore
CVE-2006-4783
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the squadID parameter.
Webspell Webspell
Webspell Webspell 4.0
685
VMScore
CVE-2009-1912
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and previous versions allows remote malicious users to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including ...
Webspell Webspell
Webspell Webspell 4.1.2
Webspell Webspell 4.1.1
Webspell Webspell 4.2.0c
Webspell Webspell 4.2.0d
Webspell Webspell 4.0.2c
Webspell Webspell 4.0
Webspell Webspell 4.01.01
Webspell Webspell 4.01.00
Webspell Webspell 4.1
Webspell Webspell 4.01.02
1 EDB exploit
755
VMScore
CVE-2006-5388
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and previous versions allows remote malicious users to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
Webspell Webspell 4.01.01
Webspell Webspell 4.0
1 EDB exploit
890
VMScore
CVE-2007-1160
webSPELL 4.0, and possibly later versions, allows remote malicious users to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
Webspell Webspell 4.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started