Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arbitrary vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-4148
DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote malicious users to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the WScript.Shell ActiveX control, related to a "script injection vulnera...
Daz3d Daz Studio 2.3.3.161
Daz3d Daz Studio 2.3.3.163
Daz3d Daz Studio 3.0.1.135
1 EDB exploit
NA
CVE-2009-1750
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
Omnisoftsol Vidsharepro
1 EDB exploit
NA
CVE-2008-3191
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile acti...
Marcioforum Mforum 0.1a
1 EDB exploit
NA
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
NA
CVE-2008-1727
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote malicious users to create arbitrary admin accounts.
Myknowledgequest Knowledgequest 2.5
Myknowledgequest Knowledgequest 2.6
1 EDB exploit
NA
CVE-2006-1704
Sire 2.0 nws allows remote malicious users to upload arbitrary image files without authentication via a direct request to upload.php.
Hubert Plisson Sire 2.0
1 EDB exploit
NA
CVE-2006-3381
SturGeoN Upload allows remote malicious users to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.
Sturgeon Upload Sturgeon Upload
1 EDB exploit
NA
CVE-2007-6479
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, w...
Dokeos Dokeos 1.8.4
1 EDB exploit
NA
CVE-2005-0698
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that...
Jason Hines Phpweblog 0.5
Jason Hines Phpweblog 0.5.2
Jason Hines Phpweblog 0.4.2
Jason Hines Phpweblog 0.5.1
Jason Hines Phpweblog 0.5.3
1 EDB exploit
NA
CVE-2008-6806
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and previous versions allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/artikel/.
7-shop 7shop
7-shop 7shop 1.0
7-shop 7shop 0.9 Beta
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »