Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
aria-security team vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-6936
Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote malicious users to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. NOTE: vector 1 likely overlaps CVE-2006-3032.
Pensacola Web Designs Xtremeasp Photogallery 2.0
1 EDB exploit
NA
CVE-2007-5679
SQL injection vulnerability in index.php in DeeEmm.com DM CMS 0.7.0.Beta allows remote malicious users to execute arbitrary SQL commands via the id parameter in the media page (build_media_content.php). NOTE: it was later reported that 0.7.4 is also affected.
Deeemm Dmcms 0.7.0
Deeemm Dmcms 0.7.4
1 EDB exploit
NA
CVE-2007-6138
SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote malicious users to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.
Vu Mass Mailer
1 EDB exploit
NA
CVE-2007-6163
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote malicious users to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information.
Gouae Dwd Realty 0
1 EDB exploit
NA
CVE-2006-5936
SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Sitexpress Sitexpress E-commerce System
1 EDB exploit
NA
CVE-2006-5987
SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote malicious users to execute arbitrary SQL commands via the a parameter.
Aspintranet Aspintranet 1.2
1 EDB exploit
NA
CVE-2006-6080
Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote malicious users to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter.
Gazatem Technologies Gnews Publisher
1 EDB exploit
NA
CVE-2006-6088
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery fie...
Blue-collar Productions I-gallery 3.4
1 EDB exploit
NA
CVE-2006-6209
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote malicious users to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_lis...
Midicart Software Midicart Asp Plus Shopping Cart
Midicart Software Midicart Asp Shopping Cart
1 EDB exploit
NA
CVE-2006-6937
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote malicious users to inject arbitrary SQL commands via the sortorder parameter.
Pensacola Web Designs Xtremeasp Photogallery 2.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »