Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
condemned vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-5217
Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
Phpc0d3r Txtcms 0.3
1 EDB exploit
NA
CVE-2008-5308
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote malicious users to change the administrator password via a direct request to modules/simpleforum/admin/index.php.
Lovecms The Simple Forum 3.1d
1 EDB exploit
NA
CVE-2008-6330
SQL injection vulnerability in index.php in MyTopix 1.3.0 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.
Jaia Interactive Mytopix
Jaia Interactive Mytopix 1.2.3
1 EDB exploit
NA
CVE-2009-0110
SQL injection vulnerability in read.php in RiotPix 0.61 and previous versions allows remote malicious users to execute arbitrary SQL commands via the forumid parameter.
Riotpix Riotpix
Riotpix Riotpix 0.60
Riotpix Riotpix 0.52
Riotpix Riotpix 0.5
Riotpix Riotpix 0.51
Riotpix Riotpix .05
1 EDB exploit
NA
CVE-2008-6919
profileedit.php TaskDriver 1.3 and previous versions allows remote malicious users to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
Taskdriver Taskdriver
Taskdriver Taskdriver 1.2
1 EDB exploit
NA
CVE-2008-7062
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads...
Lovecms Lovecms 1.6.2
1 EDB exploit
NA
CVE-2008-1509
SQL injection vulnerability in index.php in XLPortal 2.2.4 and previous versions allows remote malicious users to execute arbitrary SQL commands via the query parameter.
Xlportal Xlportal
1 EDB exploit
NA
CVE-2008-1607
SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote malicious users to execute arbitrary SQL commands via the haber parameter.
Serby Arslanhan Bomba Haber 2.0
1 EDB exploit
NA
CVE-2008-4740
Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the config[template]...
Tinycms Tinycms 1.1.2
1 EDB exploit
NA
CVE-2009-1853
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.
Kenseiboard Kensei Board 1.1.0
Kenseiboard Kensei Board
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »