Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dnx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-0735
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote malicious users to execute arbitrary SQL commands via the albums parameter.
Auracms Auracms 2.2
1 EDB exploit
NA
CVE-2007-1019
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.
Webspell Webspell 4.01.02
1 EDB exploit
NA
CVE-2007-6578
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Zeak.net Php Zlink 0.3
1 EDB exploit
NA
CVE-2007-2425
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote malicious users to read arbitrary files via a .. (dot dot) in the album parameter.
Blackdot Imageview 5.3
1 EDB exploit
NA
CVE-2007-4606
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-200...
Phpnuke-clan Phpnuke-clan
1 EDB exploit
NA
CVE-2007-5174
Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the do parameter.
Actsite Actsite 1.56
1 EDB exploit
NA
CVE-2008-3131
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the showid parameter.
Powie Psys 0.7.0
1 EDB exploit
NA
CVE-2008-3241
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Ultrastats Ultrastats 0.2.142
Ultrastats Ultrastats 0.2.136
Ultrastats Ultrastats 0.2.140
1 EDB exploit
NA
CVE-2009-1912
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and previous versions allows remote malicious users to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including ...
Webspell Webspell
Webspell Webspell 4.1.2
Webspell Webspell 4.1.1
Webspell Webspell 4.2.0c
Webspell Webspell 4.2.0d
Webspell Webspell 4.0.2c
Webspell Webspell 4.0
Webspell Webspell 4.01.01
Webspell Webspell 4.01.00
Webspell Webspell 4.1
Webspell Webspell 4.01.02
1 EDB exploit
NA
CVE-2008-6647
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote malicious users to execute arbitrary SQL commands via the gid parameter.
Ktools Photostore 3.4.3
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »