Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
girex vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2008-7064
Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and previous versions, as used in QSF Portal prior to 1.4.5, when running on Windows, allows remote malicious users to include and execute arbitrary local files via a "\"...
Quicksilver Forums Quicksilver Forums 1.4.2
1 EDB exploit
755
VMScore
CVE-2008-3153
SQL injection vulnerability in Triton CMS Pro allows remote malicious users to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
Tritoncms Triton Cms Pro
1 EDB exploit
935
VMScore
CVE-2008-1860
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and previous versions allows remote malicious users to inject arbitrary PHP code into includes/Config.php via the default parameter.
Lokicms Lokicms 0.3.1b1
Lokicms Lokicms 0.3.1b2
Lokicms Lokicms 0.3.2b1
Lokicms Lokicms
Lokicms Lokicms 0.2.0
Lokicms Lokicms 0.3.0
Lokicms Lokicms 0.1.0
Lokicms Lokicms 0.1.0rc1
1 EDB exploit
685
VMScore
CVE-2008-1911
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via a cookpass cookie.
1024 Cms 1024 Cms 1.4.2
1 EDB exploit
685
VMScore
CVE-2008-1553
Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the to parameter.
Topper Toppermod 1.0
1 EDB exploit
685
VMScore
CVE-2008-1554
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via a non-alphanumeric first character the localita parameter, which bypasses a protection mechanism.
Topper Toppermod 2.0
1 EDB exploit
755
VMScore
CVE-2008-3416
SQL injection vulnerability in modules/members.php in IceBB prior to 1.0-rc9.3 allows remote malicious users to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in...
Icebb Icebb 1.0
1 EDB exploit
505
VMScore
CVE-2008-6590
Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote malicious users to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.
Lightneasy Lightneasy 1.2.2
Sqlite Sqlite 1.2.2
1 EDB exploit
755
VMScore
CVE-2008-6592
thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and previous versions, allows remote malicious users to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_...
Sqlite Sqlite 1.2.2
Lightneasy Lightneasy 1.2.2
1 EDB exploit
755
VMScore
CVE-2008-6593
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and previous versions allows remote malicious users to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.
Lightneasy Lightneasy 1.2.2
Sqlite Sqlite 1.2.2
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »