Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webapp vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-3424
The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP prior to 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impact and remote attack vectors.
Web-app.org Webapp
6
CVSSv2
CVE-2007-1831
web-app.org WebAPP prior to 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.
Web-app.org Webapp
5
CVSSv2
CVE-2007-1832
web-app.org WebAPP prior to 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percent encoding in forms."
Web-app.org Webapp
4.3
CVSSv2
CVE-2007-1175
Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP prior to 20070209 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Web-app.org Webapp
4.3
CVSSv2
CVE-2007-1176
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP prior to 0.9.9.5 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4) the Statistics L...
Web-app.org Webapp
7.5
CVSSv2
CVE-2007-1178
WebAPP prior to 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.
Web-app.org Webapp
4.3
CVSSv2
CVE-2007-1180
WebAPP prior to 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.
Web-app.org Webapp
4.3
CVSSv2
CVE-2006-7189
Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP prior to 20060403 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to the Statistics Log Viewer.
Web-app.net Webapp 0.9.9.6
4.3
CVSSv2
CVE-2006-7190
Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP prior to 20060515 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc.
Web-app.net Webapp 0.9.9.6
7.5
CVSSv2
CVE-2007-1829
Multiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having] other [security] issues too, not as bad as letting users take over your admin account, but bad too."
Web-app.net Webapp 0.9.9.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »