Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kingoftheworld vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-5823
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and previous versions allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) in the username parameter in a Register action.
Scribe Scribe 0.2
1 EDB exploit
7.5
CVSSv2
CVE-2007-6366
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and previous versions allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_ad...
Sinecms Sinecms
1 EDB exploit
5
CVSSv2
CVE-2007-6395
Flat PHP Board 1.2 and previous versions stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain credentials via a direct request for the username php file for any user account in users/.
Flat Php Board
1 EDB exploit
4.3
CVSSv2
CVE-2007-5773
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote malicious users to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter.
Flatnuke3 Flatnuke3
1 EDB exploit
5
CVSSv2
CVE-2007-5774
index.php in the File Manager module in Flatnuke 3 allows remote malicious users to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message.
Flatnuke3 Flatnuke3
1 EDB exploit
7.5
CVSSv2
CVE-2008-0232
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.
Zero Cms Zero Cms 1.0 Alpha
1 EDB exploit
7.5
CVSSv2
CVE-2008-0233
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and previous versions allows remote malicious users to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
Zero Cms Zero Cms 1.0 Alpha
1 EDB exploit
6.8
CVSSv2
CVE-2008-7163
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and previous versions, when register_globals is enabled, allows remote malicious users to include and execute arbitrary local files via the sine[config][index_main] parameter.
Sinecms Sinecms 2.1.1
Sinecms Sinecms 2.1
Sinecms Sinecms 2.2
Sinecms Sinecms 2.2.1
Sinecms Sinecms 2.0
Sinecms Sinecms
Sinecms Sinecms 2.3.2
Sinecms Sinecms 2.3.4
1 EDB exploit
7.5
CVSSv2
CVE-2007-6159
SQL injection vulnerability in index.php in Tilde CMS 4.x and previous versions allows remote malicious users to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.
Tilde Tilde Cms 4.0
1 EDB exploit
4.3
CVSSv2
CVE-2007-6160
Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and previous versions allows remote malicious users to inject arbitrary web script or HTML via the aarstal parameter in a yeardetail action.
Tilde Tilde Cms 4.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »