Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webspell webspell vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-1154
SQL injection vulnerability in webSPELL allows remote malicious users to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
Webspell Webspell
NA
CVE-2007-1160
webSPELL 4.0, and possibly later versions, allows remote malicious users to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
Webspell Webspell 4.0
NA
CVE-2007-1163
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
Webspell Webspell 4.0
Webspell Webspell 4.01.00
Webspell Webspell
Webspell Webspell 4.01.01
1 EDB exploit
NA
CVE-2007-1155
Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED.
Webspell Webspell
NA
CVE-2007-1019
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.
Webspell Webspell 4.01.02
1 EDB exploit
NA
CVE-2007-0502
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote malicious users to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.
Webspell Webspell 4.01.02
1 EDB exploit
NA
CVE-2007-0492
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The provenance of this information is unknown; the details are obtained ...
Webspell Webspell
NA
CVE-2006-5388
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and previous versions allows remote malicious users to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
Webspell Webspell 4.0
Webspell Webspell 4.01.01
1 EDB exploit
NA
CVE-2006-4782
src/index.php in WebSPELL 4.01.01 and previous versions, when register_globals is enabled, allows remote malicious users to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.
Webspell Webspell
Webspell Webspell 4.1
Webspell Webspell 4.0
Webspell Webspell 4.1.1
1 EDB exploit
NA
CVE-2006-4783
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the squadID parameter.
Webspell Webspell
Webspell Webspell 4.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2018-25103
CVE-2024-36279
CVE-2024-38457
elevation of privilege
CVE-2024-27801
CVE-2024-30103
NULL pointer dereference
CVE-2024-6057
XML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »