Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
omer singer vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-5386
Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote malicious users to inject arbitrary web script or HTML via the query string.
Phpmyadmin Phpmyadmin 2.11.1
1 EDB exploit
NA
CVE-2007-5589
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin prior to 2.11.1.2 allow remote malicious users to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) display_change_password....
Phpmyadmin Phpmyadmin
1 EDB exploit
NA
CVE-2007-6696
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote malicious users to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authe...
Webcalendar Webcalendar 1.1.6
2 EDB exploits
NA
CVE-2008-4651
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.
Jetbox Jetbox Cms 2.1
2 EDB exploits
NA
CVE-2008-0540
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote malicious users to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
Trixbox Trixbox 2.4.2.0
2 EDB exploits
NA
CVE-2008-6637
Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote malicious users to inject arbitrary web script or HTML via the (1) school and (2) email parameters.
Libraryvideocompany Safari Montage
1 EDB exploit
NA
CVE-2008-6097
Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog prior to 1.7.1 allow remote malicious users to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to index.php/Edit/Main/Home, (3) to parameter...
Wikyblog Wikyblog 1.6.1.7
Wikyblog Wikyblog 1.6
Wikyblog Wikyblog 1.5.7.2
Wikyblog Wikyblog 1.5.7
Wikyblog Wikyblog 1.5.0.2
Wikyblog Wikyblog 1.5
Wikyblog Wikyblog 1.7
Wikyblog Wikyblog 1.6.1.4
Wikyblog Wikyblog 1.6.1.3
Wikyblog Wikyblog 1.6.1.2
Wikyblog Wikyblog 1.4.14
Wikyblog Wikyblog 1.4.13
Wikyblog Wikyblog 1.4.5
Wikyblog Wikyblog 1.4.4
Wikyblog Wikyblog 1.4.12
Wikyblog Wikyblog 1.5.7.4
Wikyblog Wikyblog 1.5.7.3
Wikyblog Wikyblog 1.5.1
Wikyblog Wikyblog 1.5.0.3
Wikyblog Wikyblog 1.7.1.1
Wikyblog Wikyblog 1.7.0.1
Wikyblog Wikyblog 1.6.1.6
1 EDB exploit
NA
CVE-2008-4459
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote malicious users to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information.
Extrovert Software Thyme 1.3
1 EDB exploit
NA
CVE-2007-6564
Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote malicious users to inject arbitrary web script or HTML via the com_option parameter.
Limbo Cms Limbo Cms 1.0.4.2
1 EDB exploit
NA
CVE-2008-6174
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote malicious users to inject arbitrary web script or HTML via the liste parameter.
Jetbox Jetbox Cms 2.1
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started