Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
condemned vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2008-5593
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
Bpowerhouse Mini Cms 1.0.1
1 EDB exploit
7.5
CVSSv2
CVE-2008-5594
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
Bpowerhouse Mini Blog 1.0.1
1 EDB exploit
6.8
CVSSv2
CVE-2008-5604
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the action parameter.
Drennansoft My Simple Forum 3.0
Drennansoft My Simple Forum 4.1
1 EDB exploit
6.8
CVSSv2
CVE-2009-4426
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.
Launchpad Ignition 1.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-5308
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote malicious users to change the administrator password via a direct request to modules/simpleforum/admin/index.php.
Lovecms The Simple Forum 3.1d
1 EDB exploit
5
CVSSv2
CVE-2008-5794
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote malicious users to delete arbitrary files via a .. (dot dot) in the delete parameter.
Lovecms Lovecms 1.6.2
1 EDB exploit
5
CVSSv2
CVE-2008-5218
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote malicious users to obtain cleartext passwords.
Scriptsez Freeze Greetings 1.0
1 EDB exploit
7.5
CVSSv2
CVE-2008-3848
SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Pdesigner Z-breaknews 2.0
1 EDB exploit
7.5
CVSSv2
CVE-2008-3588
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote malicious users to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.
Phsblog Phsblog 0.1.1
1 EDB exploit
6.5
CVSSv2
CVE-2008-3718
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.
Cyberbb Cyberbb 0.6
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37884
CVE-2024-6003
remote
brute force
information disclosure
CVE-2024-27801
CVE-2024-30078
CVE-2024-31870
CVE-2024-6042
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »