Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zorlu vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-6944
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.
Scriptsfeed Auto Classifieds -
3 EDB exploits
NA
CVE-2008-2449
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the pr...
Ikemcg Phpinstantgallery 2.0
2 EDB exploits
NA
CVE-2008-7140
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this...
Alexguestbook \\@lex Guestbook
Alexguestbook \\@lex Guestbook 3.13
Alexguestbook \\@lex Guestbook 3.12
Alexguestbook \\@lex Guestbook 4.0.4
Alexguestbook \\@lex Guestbook 4.0.2
Alexguestbook \\@lex Guestbook 4.0.1
2 EDB exploits
NA
CVE-2008-6206
Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote malicious users to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details a...
Robotstats Robotstats 0.1
2 EDB exploits
NA
CVE-2008-5307
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote malicious users to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information.
Pilot Group Pg Real Roommate Finder Solution Nil
2 EDB exploits
NA
CVE-2008-1511
Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote malicious users to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is...
Oocomments Oocomments 1.0
2 EDB exploits
NA
CVE-2008-1296
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote malicious users to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. NOTE: the provenance of this information is unknown;...
Encaps Encapsgallery 1.11.2
2 EDB exploits
NA
CVE-2008-5571
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote malicious users to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained...
Dotnetindex Professional Download Assistant 0.1
2 EDB exploits
NA
CVE-2008-6269
Joovili 3.1.4 allows remote malicious users to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) session_id, session_logged_in, and session_username cookies for user privileges; (2) session_admin_id, session_admin_username, ...
Joovili Joovili 3.1.4
1 EDB exploit
NA
CVE-2008-5288
PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the config_path parameter.
Scripts4you Faq Manager 1.2
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »