Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
staker vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-4486
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and previous versions, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
Yerba Yerba
Yerba Yerba 6.28
2 EDB exploits
NA
CVE-2008-4203
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and previous versions allows remote malicious users to execute arbitrary SQL commands via a recook cookie.
Czaries Czarnews 1.12
Czaries Czarnews
Czaries Czarnews 1.13
Czaries Czarnews 1.14
2 EDB exploits
NA
CVE-2007-6586
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote malicious users to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.
Niclor Niclor 16 04 06
2 EDB exploits
NA
CVE-2008-5841
Multiple SQL injection vulnerabilities in iGaming 1.5 and previous versions allow remote malicious users to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.
Igamingcms Igaming Cms 1.3.1
Igamingcms Igaming Cms 1.4.2
Igamingcms Igaming Cms
2 EDB exploits
NA
CVE-2008-1918
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action....
Php-fusion Php-fusion 6.01.14
Php-fusion Php-fusion 6.00.307
2 EDB exploits
NA
CVE-2008-6734
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the action parameter.
Keller Web Admin Kwa 0.94
2 EDB exploits
NA
CVE-2008-6795
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote malicious users to execute arbitrary SQL commands via the nID parameter.
Niclor Vibro-school-cms
2 EDB exploits
NA
CVE-2008-4592
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the p parameter.
Sportspanel Sports Clubs Web Portal 0.0.1
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7