Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arbitrary vulnerabilities and exploits
(subscribe to this query)
505
VMScore
CVE-2009-0753
Absolute path traversal vulnerability in MLDonkey 2.8.4 up to and including 2.9.7 allows remote malicious users to read arbitrary files via a leading "//" (double slash) in the filename.
Mldonkey Mldonkey 2.9.0-r3
Mldonkey Mldonkey 2.9.7
Mldonkey Mldonkey 2.8.4
Mldonkey Mldonkey 2.9
Mldonkey Mldonkey 2.8.7
1 EDB exploit
685
VMScore
CVE-2007-5720
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote malicious users to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
Profilecms Profilecms 1.0
1 EDB exploit
1000
VMScore
CVE-1999-1479
The textcounter.pl by Matt Wright allows remote malicious users to execute arbitrary commands via shell metacharacters.
Matt Wright Textcounter 1.2
1 EDB exploit
755
VMScore
CVE-2007-5230
admin/upload_files.php in Zomplog 3.8.1 and previous versions does not check for administrative credentials, which allows remote malicious users to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
Zomplog Zomplog 3.7.6
Zomplog Zomplog 3.8
Zomplog Zomplog 3.8.1
Zomplog Zomplog 3.7
1 EDB exploit
465
VMScore
CVE-2007-5231
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and previous versions allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers ...
Zomplog Zomplog 3.8
Zomplog Zomplog 3.8.1
Zomplog Zomplog 3.7
Zomplog Zomplog 3.7.6
1 EDB exploit
435
VMScore
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
755
VMScore
CVE-2001-0274
kicq IRC client 1.0.0, and possibly later versions, allows remote malicious users to execute arbitrary commands via shell metacharacters in a URL.
Kicq Kicq 1.0.0
1 EDB exploit
655
VMScore
CVE-2017-14838
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
Teamworktec Job Links -
1 EDB exploit
605
VMScore
CVE-2009-1750
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
Omnisoftsol Vidsharepro
1 EDB exploit
505
VMScore
CVE-2006-1704
Sire 2.0 nws allows remote malicious users to upload arbitrary image files without authentication via a direct request to upload.php.
Hubert Plisson Sire 2.0
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »