Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
book vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-4578
export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote malicious users to obtain sensitive information.
The Address Book The Address Book 1.04e
6.8
CVSSv2
CVE-2006-4577
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote malicious users to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (...
The Address Book The Address Book 1.04e
7.5
CVSSv2
CVE-2006-4580
register.php in The Address Book 1.04e allows remote malicious users to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".
The Address Book The Address Book 1.04e
NA
CVE-2023-1126
The WP FEvents Book WordPress plugin up to and including 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks
Wp Fevents Book Project Wp Fevents Book
NA
CVE-2023-1129
The WP FEvents Book WordPress plugin up to and including 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
Wp Fevents Book Project Wp Fevents Book
4.3
CVSSv2
CVE-2022-1842
The OpenBook Book Data WordPress plugin up to and including 3.5.2 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of san...
Openbook Book Data Project Openbook Book Data
NA
CVE-2021-34249
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote malicious users to view sensitive information via the id paremeter in application URL.
Online Book Store Project Online Book Store 1.0
5
CVSSv2
CVE-2020-24115
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
Online Book Store Project Online Book Store 1.0
4.3
CVSSv2
CVE-2005-3037
Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote malicious users to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.
Handy Address Book Handy Address Book Server 1.1
7.5
CVSSv2
CVE-2020-23763
SQL injection in admin.php in Online Book Store 1.0 allows remote malicious users to execute arbitrary SQL commands and bypass authentication.
Online Book Store Project Online Book Store 1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »