Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
byalbayx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-1748
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote malicious users to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.
Joost Horward Catviz 0.4.0
1 EDB exploit
NA
CVE-2009-1749
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote malicious users to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.
Joost Horward Catviz 0.4.0
1 EDB exploit
NA
CVE-2009-1752
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote malicious users to gain privileges a direct request. NOTE: some of these details are obtained from third party information.
Exjune Office Message System 1
1 EDB exploit
NA
CVE-2009-1495
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download a database via a direct request for data/db.mdb.
Webfileexplorer Web File Explorer 3.1
1 EDB exploit
NA
CVE-2009-0602
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.
Wikkitikkitavi Wikkitikkitavi 1.11
1 EDB exploit
NA
CVE-2009-0459
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote malicious users to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of ...
Wholehogsoftware Password Protect 1.0
2 EDB exploits
NA
CVE-2009-0458
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote malicious users to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details ...
Wholehogsoftware Ware Support 1.0
2 EDB exploits
NA
CVE-2009-0281
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote malicious users to execute arbitrary SQL commands via the (1) username and (2) password parameters.
Warhound Walking Club
1 EDB exploit
NA
CVE-2009-0252
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote malicious users to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are o...
Enthrallweb Ereservations
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2