Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
stefan schurtz vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2011-4713
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.
Oscss Oscss
Oscss Oscss 1.1
Oscss Oscss 2.10
Oscss Oscss 1.2.2
Oscss Oscss 1.0
1 EDB exploit
7.5
CVSSv2
CVE-2012-6520
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote malicious users to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.
Wikidforum Wikidforum 2.10
1 EDB exploit
4.3
CVSSv2
CVE-2012-6528
Multiple cross-site scripting (XSS) vulnerabilities in ATutor prior to 2.1 allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_reminder.php, (5) login.p...
Atutor Atutor 1.5.3.1
Atutor Atutor 1.6.1
Atutor Atutor 1.4.2
Atutor Atutor 1.4.1
Atutor Atutor 1.3.1
Atutor Atutor 1.3
Atutor Atutor 2.0.2
Atutor Atutor 2.0.1
Atutor Atutor 1.6.4
Atutor Atutor 1.6
Atutor Atutor 1.5.1
Atutor Atutor 1.4.3
Atutor Atutor 1.2.2
Atutor Atutor
Atutor Atutor 1.5.4
Atutor Atutor 1.5.5
Atutor Atutor 1.5.3
Atutor Atutor 1.3.3
Atutor Atutor 1.3.2
Atutor Atutor 2.0.3
Atutor Atutor 1.5.3.2
Atutor Atutor 1.5.2
1 EDB exploit
4
CVSSv2
CVE-2012-5905
Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.
Elif Keir Knftpd 1.0.0
1 EDB exploit
4.3
CVSSv2
CVE-2012-5913
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.
Wordpress Integrator Project Wordpress Integrator 1.32
1 EDB exploit
4.3
CVSSv2
CVE-2012-0900
Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.
Beehive Forum Beehive Forum 1.0.1
1 EDB exploit
7.5
CVSSv2
CVE-2012-1911
Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE...
Chatelao Php Address Book 6.2.9
Chatelao Php Address Book 6.2.7
Chatelao Php Address Book 6.2
Chatelao Php Address Book 6.1.4
Chatelao Php Address Book 5.7.3
Chatelao Php Address Book 5.8.1
Chatelao Php Address Book 5.7.5
Chatelao Php Address Book 5.4.4
Chatelao Php Address Book 5.4.3
Chatelao Php Address Book 5.0
Chatelao Php Address Book 5.4.2
Chatelao Php Address Book 4.0.2
Chatelao Php Address Book 3.2.6
Chatelao Php Address Book 3.2.13
Chatelao Php Address Book 3.1.5
Chatelao Php Address Book 3.2.5
Chatelao Php Address Book 3.3.8
Chatelao Php Address Book 3.3
Chatelao Php Address Book 3.2.14
Chatelao Php Address Book 3.4.7
Chatelao Php Address Book 3.4.8
Chatelao Php Address Book 3.4.3
1 EDB exploit
4.3
CVSSv2
CVE-2012-1912
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.
Chatelao Php Address Book 6.1
Chatelao Php Address Book 6.2
Chatelao Php Address Book 6.2.7
Chatelao Php Address Book 6.2.9
Chatelao Php Address Book 5.8.1
Chatelao Php Address Book 5.7.5
Chatelao Php Address Book 5.4.4
Chatelao Php Address Book 5.4.3
Chatelao Php Address Book 5.5
Chatelao Php Address Book 5.4.2
Chatelao Php Address Book 5.4.1
Chatelao Php Address Book 4.0.2
Chatelao Php Address Book 3.2.6
Chatelao Php Address Book 3.1.5
Chatelao Php Address Book 3.1.6
Chatelao Php Address Book 3.3.8
Chatelao Php Address Book 3.3.7
Chatelao Php Address Book 3.3
Chatelao Php Address Book 3.2.14
Chatelao Php Address Book 3.4.8
Chatelao Php Address Book 3.4.5
Chatelao Php Address Book 3.4.4
1 EDB exploit
4.3
CVSSv2
CVE-2012-2331
Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity prior to 1.6.1 allows remote malicious users to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-...
S9y Serendipity
S9y Serendipity 0.9.1
S9y Serendipity 1.2.1
S9y Serendipity 0.7.1
S9y Serendipity 0.8.1
S9y Serendipity 1.3
S9y Serendipity 1.0
S9y Serendipity 1.1
S9y Serendipity 1.4
S9y Serendipity 0.7
S9y Serendipity 1.0.4
S9y Serendipity 1.1.4
S9y Serendipity 1.1.1
S9y Serendipity 1.5.1
S9y Serendipity 1.4.1
S9y Serendipity 0.4
S9y Serendipity 0.3
S9y Serendipity 0.9
S9y Serendipity 0.8.5
S9y Serendipity 0.8.4
S9y Serendipity 0.8.3
S9y Serendipity 0.8.2
1 EDB exploit
7.5
CVSSv2
CVE-2012-2332
SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity prior to 1.6.1 allows remote malicious users to execute arbitrary SQL commands via the serendipity[plugin_to_conf] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF)...
S9y Serendipity 0.8.4
S9y Serendipity 0.9.1
S9y Serendipity 1.1.1
S9y Serendipity 0.7.1
S9y Serendipity 1.5.4
S9y Serendipity 1.5.3
S9y Serendipity 0.4
S9y Serendipity 1.1
S9y Serendipity 1.2.1
S9y Serendipity 1.2
S9y Serendipity 0.7
S9y Serendipity 1.0.4
S9y Serendipity 1.3
S9y Serendipity 1.1.2
S9y Serendipity 1.0
S9y Serendipity 1.5.1
S9y Serendipity 1.4.1
S9y Serendipity
S9y Serendipity 0.9
S9y Serendipity 0.8
S9y Serendipity 0.8.1
S9y Serendipity 1.6.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »