Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hamid ebadi vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2009-4018
The proc_open function in ext/standard/proc_open.c in PHP prior to 5.2.11 and 5.3.x prior to 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent malicious users to execute programs with an arbit...
Php Php 4.3.1
Php Php 4.3.2
Php Php 4.1.0
Php Php 4.2.1
Php Php 4.4.7
Php Php 5.0
Php Php 4.3.9
Php Php 4.4.0
Php Php 5.0.4
Php Php 5.0.3
Php Php 5.0.0
Php Php 1.0
Php Php 4
Php Php 3.0.2
Php Php 3.0.18
Php Php 4.0
Php Php 3.0.9
Php Php 4.0.1
Php Php 4.0.5
Php Php 4.0.4
Php Php 4.3.11
Php Php 4.3.4
1 EDB exploit
505
VMScore
CVE-2007-2252
Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and previous versions allows remote malicious users to obtain sensitive information via a .. (dot dot) in the icodir parameter.
Exponent Exponent Cms 0.96.5 Rc1
Exponent Exponent Cms 0.96.6 Alpha
1 EDB exploit
435
VMScore
CVE-2008-6938
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote malicious users to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI di...
Holger Zimmermann Pi3web
Holger Zimmermann Pi3web 1.0.1
Holger Zimmermann Pi3web 2.0
Holger Zimmermann Pi3web 2.0.1
Holger Zimmermann Pi3web 2.0.2 Beta 1
1 EDB exploit
755
VMScore
CVE-2006-0721
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote malicious users to execute arbitrary SQL commands via the to_userid parameter.
Runcms Runcms 1.3a
Runcms Runcms 1.3a2
Runcms Runcms 1.2
1 EDB exploit
405
VMScore
CVE-2006-3184
Direct static code injection vulnerability in ASP Stats Generator prior to 2.1.2 allows remote authenticated malicious users to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
Asp Stats Generator Asp Stats Generator
1 EDB exploit
515
VMScore
CVE-2006-3361
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP paramet...
Stud.ip Stud.ip
1 EDB exploit
755
VMScore
CVE-2006-3580
SQL injection vulnerability in pages.asp in ASP Stats Generator prior to 2.1.2 allows remote malicious users to execute arbitrary SQL commands via the order parameter.
Asp Stats Generator Asp Stats Generator
1 EDB exploit
755
VMScore
CVE-2006-1081
SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote malicious users to execute arbitrary SQL commands via the email parameter.
Jonathan Beckett Pluggedout Nexus 0.1
1 EDB exploit
645
VMScore
CVE-2006-1773
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.
Phpkit Phpkit
1 EDB exploit
650
VMScore
CVE-2006-0660
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and previous versions allows remote malicious users to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbi...
Farsinews Farsinews 2.1
Farsinews Farsinews 2.1 Beta2
Farsinews Farsinews 2.5
2 EDB exploits
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2