Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dynpg vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote malicious users to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are o...
Dynpg Dynpg 4.2.0
Dynpg Dynpg 4.1.1
1 EDB exploit
520
VMScore
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.ph...
Dynpg Dynpg
2 EDB exploits
312
VMScore
CVE-2021-27527
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "valueID" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27530
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote malicious user to inject javascript via URI in /index.php.
Dynpg Dynpg 4.9.2
505
VMScore
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote malicious users to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Dynpg Dynpg 4.2.0
1 EDB exploit
755
VMScore
CVE-2010-4400
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote malicious users to execute arbitrary SQL commands via the giveRights_UserId parameter.
Dynpg Dynpg 4.2.0
1 EDB exploit
312
VMScore
CVE-2021-27528
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "refID" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27526
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "page" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27529
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "limit" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27531
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "query" parameter.
Dynpg Dynpg 4.9.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »