Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
web-app.org webapp vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-1186
WebAPP prior to 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
Web-app.org Webapp 0.9.9.2
Web-app.org Webapp 0.9.9.2.1
Web-app.org Webapp 0.9.9.3
Web-app.org Webapp 0.9.9.3.1
Web-app.org Webapp 0.9.9.3.2
Web-app.org Webapp 0.9.9.4
Web-app.org Webapp 0.9.9
Web-app.org Webapp 0.9.9.1
NA
CVE-2006-1427
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter i...
Web-app.org Webapp 0.9.9.3.2
Web-app.org Webapp 0.9.9.1
Web-app.org Webapp 0.9.9.2
Web-app.org Webapp 0.9.9.2.1
Web-app.org Webapp 0.9.9.3
Web-app.org Webapp 0.9.9.3.1
2 EDB exploits
NA
CVE-2005-0927
Unknown vulnerability in subs.pl for WebAPP 0.9.9 up to and including 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.
Web-app.org Webapp 0.9.9
Web-app.org Webapp 0.9.9.2
Web-app.org Webapp 0.9.9.1
NA
CVE-2007-1489
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote malicious users to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vul...
Web-app.org Webapp 0.9.9.6
Web-app.org Webapp 0.9.9.4
Web-app.org Webapp 0.9.9.5
NA
CVE-2005-1628
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote malicious users to execute arbitrary commands via shell metacharacters in the f parameter.
Web-app.org Webapp 0.9.9.2.1
Web-app.org Webapp 0.9.9.2
Web-app.org Webapp 0.9.9
2 EDB exploits
NA
CVE-2007-3418
The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP prior to 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authenticated users to impersonate other users.
Web-app.org Webapp
NA
CVE-2007-3419
The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP prior to 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.dat, (6) states.dat, and (7) ages.dat files before saving profile settings of me...
Web-app.org Webapp
NA
CVE-2007-3421
The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP prior to 0.9.9.7 do not verify presence of users in memberlist.dat, which has unknown impact...
Web-app.org Webapp
NA
CVE-2007-3423
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP prior to 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, wh...
Web-app.org Webapp
NA
CVE-2007-1175
Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP prior to 20070209 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Web-app.org Webapp
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »