Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zorlu vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-6913
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request t...
Zeeways Zeejobsite 2.0
1 EDB exploit
NA
CVE-2008-6915
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote malicious users to inject arbitrary web script or HTML via the propid parameter.
Zeeways Zeeproperty 1.0
1 EDB exploit
NA
CVE-2008-6914
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct reque...
Zeeways Zeeproperty 1.0
1 EDB exploit
NA
CVE-2009-2640
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote malicious users to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.
Interlogy Profile Manager -
1 EDB exploit
NA
CVE-2008-6871
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote malicious users to obtain unspecified sensitive information via a direct request.
Merlix Educate Server -
1 EDB exploit
NA
CVE-2008-6870
Merlix Educate Server allows remote malicious users to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
Merlix Educate Server -
1 EDB exploit
NA
CVE-2008-6804
Tribiq CMS 5.0.9a beta allows remote malicious users to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue
Tribiq Tribiq Cms 5.0.9a
1 EDB exploit
NA
CVE-2009-1504
Absolute Form Processor XE 1.5 allows remote malicious users to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
Xigla Absolute Control Panel Xe 1.5
1 EDB exploit
NA
CVE-2009-1502
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the page parameter.
Matteoiammarrone S-cms 1.5.2
Matteoiammarrone S-cms 1.1
1 EDB exploit
NA
CVE-2008-6720
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).
Deltascripts Php Links
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »