Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dnx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-20191
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote malicious user to bypass a configured ACL. This vulnerability is due to incomplete support for this feature. An ...
Cisco Ios Xr 7.10
Cisco Ios Xr
6.8
CVSSv2
CVE-2009-2337
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the spam_id parameter.
W3bcms Gaestebuch Guestbook Module 3.0.0
1 EDB exploit
6.8
CVSSv2
CVE-2009-1912
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and previous versions allows remote malicious users to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including ...
Webspell Webspell
Webspell Webspell 4.1.2
Webspell Webspell 4.1.1
Webspell Webspell 4.2.0c
Webspell Webspell 4.2.0d
Webspell Webspell 4.0.2c
Webspell Webspell 4.0
Webspell Webspell 4.01.01
Webspell Webspell 4.01.00
Webspell Webspell 4.1
Webspell Webspell 4.01.02
1 EDB exploit
7.5
CVSSv2
CVE-2008-6647
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote malicious users to execute arbitrary SQL commands via the gid parameter.
Ktools Photostore 3.4.3
2 EDB exploits
7.5
CVSSv2
CVE-2008-6648
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote malicious users to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.
Ktools Photostore 3.4.3
Ktools Photostore 3.5.2
2 EDB exploits
7.5
CVSSv2
CVE-2008-6649
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions up to and including 3.5.2 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Ktools Photostore 3.1.0
Ktools Photostore 3.1.1
Ktools Photostore 3.2
Ktools Photostore 3.2.1
Ktools Photostore 3.5.2
Ktools Photostore 3.4
Ktools Photostore 3.4.2
Ktools Photostore 3.4.3
Ktools Photostore 2.5
Ktools Photostore 2.9.8
Ktools Photostore 3.5
Ktools Photostore 3.5.1
2 EDB exploits
10
CVSSv2
CVE-2008-6158
Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) prior to 3.2.0 have unknown impact and remote attack vectors.
W3bcms W3b\\>cms
W3bcms W3b\\>cms 3.0.5
1 EDB exploit
6.8
CVSSv2
CVE-2009-0597
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) prior to 3.4.0, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.
W3b Cms Aka W3blabor Cms
1 EDB exploit
7.5
CVSSv2
CVE-2008-3241
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Ultrastats Ultrastats 0.2.142
Ultrastats Ultrastats 0.2.136
Ultrastats Ultrastats 0.2.140
1 EDB exploit
6.8
CVSSv2
CVE-2008-3131
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the showid parameter.
Powie Psys 0.7.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »