Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
r0t vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-2140
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and previous versions allow remote malicious users to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
Orbitscripts Orbithyip 2.0
2 EDB exploits
NA
CVE-2005-3872
Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORUM_ID, and (4) CAT_ID parameters in topic.php.
Ugroup Ugroup
2 EDB exploits
NA
CVE-2005-3877
Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.
Cafuego Simple Document Management System 1.1.5
Cafuego Simple Document Management System
Cafuego Simple Document Management System 1.1.4
Cafuego Simple Document Management System 1.1.6
2 EDB exploits
NA
CVE-2005-3943
Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; and (3) CATEGORY_ID parameter in (b) index.php.
2 EDB exploits
NA
CVE-2005-3875
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and previous versions allow remote malicious users to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.
Enterprise Heart Enterprise Connector
2 EDB exploits
NA
CVE-2005-3920
SQL injection vulnerability in Babe Logger 2 allows remote malicious users to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.
Babe Logger Babe Logger 2
2 EDB exploits
NA
CVE-2005-3986
Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.
Verosky Media Instant Photo Gallery
2 EDB exploits
NA
CVE-2005-4064
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote malicious users to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
Alan Ward A-faq 1.0
2 EDB exploits
NA
CVE-2005-4071
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread...
Cfmagic Magic Forum Personal
2 EDB exploits
NA
CVE-2005-4484
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.
Iatek Intranetapp
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »