Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arbitrary vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2008-6660
Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote malicious users to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct request. NOTE: some of...
Ozerov Bigdump 029b
1 EDB exploit
6.5
CVSSv2
CVE-2008-2488
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.
Beaussier Roomphplanning 1.5
1 EDB exploit
7.5
CVSSv2
CVE-2008-2574
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote malicious users to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in tus_imagenes/.
Flashblog Flashblog 0.31
1 EDB exploit
6
CVSSv2
CVE-2014-3782
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear prior to 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some ...
Dotclear Dotclear 2.6.1
Dotclear Dotclear 2.6
Dotclear Dotclear
9.4
CVSSv2
CVE-2021-46424
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote malicious user to delete any file, even system internal files, via a DELETE request.
Telesquare Tlr-2005ksh Firmware 1.0.0
7.5
CVSSv2
CVE-2009-3949
cp/profile.php in VivaPrograms Infinity 2.0.5 and previous versions does not require administrative authentication for the donewauthor action, which allows remote malicious users to create administrative accounts via the name, password, and conf_password parameters.
Vivaprograms Infinity Script
Vivaprograms Infinity Script 2.0.0
1 EDB exploit
10
CVSSv2
CVE-1999-1479
The textcounter.pl by Matt Wright allows remote malicious users to execute arbitrary commands via shell metacharacters.
Matt Wright Textcounter 1.2
1 EDB exploit
4.3
CVSSv2
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
6.5
CVSSv2
CVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
Teamworktec Photo Fusion -
1 EDB exploit
6.5
CVSSv2
CVE-2008-3093
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and previous versions allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.
Phplizardo Imperialbb
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »