Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zorlu vulnerabilities and exploits
(subscribe to this query)
665
VMScore
CVE-2008-6943
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
Scriptsfeed Recipes Listing Portal
3 EDB exploits
440
VMScore
CVE-2008-7140
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this...
Alexguestbook \\@lex Guestbook
Alexguestbook \\@lex Guestbook 3.13
Alexguestbook \\@lex Guestbook 3.12
Alexguestbook \\@lex Guestbook 4.0.4
Alexguestbook \\@lex Guestbook 4.0.2
Alexguestbook \\@lex Guestbook 4.0.1
2 EDB exploits
440
VMScore
CVE-2008-2449
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the pr...
Ikemcg Phpinstantgallery 2.0
2 EDB exploits
440
VMScore
CVE-2008-1296
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote malicious users to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. NOTE: the provenance of this information is unknown;...
Encaps Encapsgallery 1.11.2
2 EDB exploits
760
VMScore
CVE-2008-6206
Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote malicious users to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details a...
Robotstats Robotstats 0.1
2 EDB exploits
760
VMScore
CVE-2008-1511
Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote malicious users to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is...
Oocomments Oocomments 1.0
2 EDB exploits
760
VMScore
CVE-2008-5307
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote malicious users to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information.
Pilot Group Pg Real Roommate Finder Solution Nil
2 EDB exploits
760
VMScore
CVE-2008-5571
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote malicious users to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained...
Dotnetindex Professional Download Assistant 0.1
2 EDB exploits
505
VMScore
CVE-2008-6870
Merlix Educate Server allows remote malicious users to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
Merlix Educate Server -
1 EDB exploit
755
VMScore
CVE-2010-4856
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote malicious users to execute arbitrary SQL commands via the tarih parameter.
Aspindir Xweblog 2.2
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »