Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
condemned vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2009-4426
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.
Launchpad Ignition 1.2
1 EDB exploit
6.8
CVSSv2
CVE-2008-7062
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads...
Lovecms Lovecms 1.6.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-6919
profileedit.php TaskDriver 1.3 and previous versions allows remote malicious users to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
Taskdriver Taskdriver
Taskdriver Taskdriver 1.2
1 EDB exploit
7.5
CVSSv2
CVE-2009-1853
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.
Kenseiboard Kensei Board 1.1.0
Kenseiboard Kensei Board
1 EDB exploit
7.5
CVSSv2
CVE-2009-1509
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Myiosoft Ajaxportal 3.0
1 EDB exploit
6.5
CVSSv2
CVE-2008-6330
SQL injection vulnerability in index.php in MyTopix 1.3.0 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.
Jaia Interactive Mytopix
Jaia Interactive Mytopix 1.2.3
1 EDB exploit
7.5
CVSSv2
CVE-2008-5949
Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote malicious users to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5) workspace.php in includes...
Tiddlywiki Cctiddly 1.7.4
Tiddlywiki Cctiddly 1.7.6
2 EDB exploits
7.5
CVSSv2
CVE-2009-0110
SQL injection vulnerability in read.php in RiotPix 0.61 and previous versions allows remote malicious users to execute arbitrary SQL commands via the forumid parameter.
Riotpix Riotpix
Riotpix Riotpix 0.60
Riotpix Riotpix 0.52
Riotpix Riotpix 0.5
Riotpix Riotpix 0.51
Riotpix Riotpix .05
1 EDB exploit
5
CVSSv2
CVE-2008-5794
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote malicious users to delete arbitrary files via a .. (dot dot) in the delete parameter.
Lovecms Lovecms 1.6.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-5593
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.
Bpowerhouse Mini Cms 1.0.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »