Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cyber-zone vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-6356
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb.
Donnafontenot Evcal Events Calendar -
1 EDB exploit
NA
CVE-2008-6371
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote malicious users to execute arbitrary SQL commands via the username (Username parameter).
Ocean12tech Membership Manager Pro -
1 EDB exploit
NA
CVE-2008-6380
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote malicious users to execute arbitrary SQL commands via the CategoryID parameter.
Activewebsoftwares Active Web Helpdesk 2.0
1 EDB exploit
NA
CVE-2008-6387
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download the database file via a direct request to qtv.mdb.
Activewebsoftwares Quick Tree View .net 3.1
1 EDB exploit
NA
CVE-2008-6390
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote malicious users to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information...
Ocean12tech Membership Manager Pro -
1 EDB exploit
NA
CVE-2008-6796
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote malicious users to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).
Preprojects Pre Real Estate Listings
1 EDB exploit
NA
CVE-2008-5047
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote malicious users to execute arbitrary SQL commands via the username parameter.
Mole Group Rental Script
1 EDB exploit
NA
CVE-2008-5292
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote malicious users to execute arbitrary SQL commands via the type parameter.
Videogirls Videogirls Biz Nil
1 EDB exploit
NA
CVE-2009-1746
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote malicious users to execute arbitrary SQL commands via the id parameter in a detail action.
Diangemilang Dgnews 3.0 Beta
1 EDB exploit
NA
CVE-2008-6580
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.
Funscripts Red Reservations -
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30078
CVE-2024-37896
code injection
CVE-2024-3080
CVE-2024-5172
cross-site request forgery
CVE-2024-6111
firmware
CVE-2024-38504
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »