Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webspell webspell vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2007-1160
webSPELL 4.0, and possibly later versions, allows remote malicious users to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
Webspell Webspell 4.0
7.5
CVSSv2
CVE-2010-4861
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote malicious users to execute arbitrary SQL commands via the search parameter.
Webspell Webspell 4.2.1
1 EDB exploit
7.5
CVSSv2
CVE-2007-4028
Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote malicious users to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information.
Webspell Webspell 4.01.02
7.5
CVSSv2
CVE-2007-1163
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
Webspell Webspell
Webspell Webspell 4.0
Webspell Webspell 4.01.00
Webspell Webspell 4.01.01
1 EDB exploit
7.5
CVSSv2
CVE-2007-0502
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote malicious users to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.
Webspell Webspell 4.01.02
1 EDB exploit
7.5
CVSSv2
CVE-2007-0492
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The provenance of this information is unknown; the details are obtained ...
Webspell Webspell
7.5
CVSSv2
CVE-2006-5388
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and previous versions allows remote malicious users to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
Webspell Webspell 4.01.01
Webspell Webspell 4.0
1 EDB exploit
7.5
CVSSv2
CVE-2006-0728
SQL injection vulnerability in search.php in webSPELL 4.01.00 and previous versions allows remote malicious users to inject arbitrary SQL commands via the title_op parameter.
Webspell Webspell
1 EDB exploit
6.8
CVSSv2
CVE-2009-1912
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and previous versions allows remote malicious users to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including ...
Webspell Webspell
Webspell Webspell 4.1.2
Webspell Webspell 4.1.1
Webspell Webspell 4.2.0c
Webspell Webspell 4.2.0d
Webspell Webspell 4.0.2c
Webspell Webspell 4.0
Webspell Webspell 4.01.01
Webspell Webspell 4.01.00
Webspell Webspell 4.1
Webspell Webspell 4.01.02
1 EDB exploit
6.8
CVSSv2
CVE-2007-1154
SQL injection vulnerability in webSPELL allows remote malicious users to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
Webspell Webspell
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
CVE-2023-52162
CVE-2024-23670
CVE-2024-5404
man-in-the-middle
CVE-2024-5214
CVE-2024-4358
CVE-2024-20696
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »