Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
doz vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2006-6861
Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote malicious users to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp.
Outfront Spooky Login 2.7
1 EDB exploit
7.5
CVSSv2
CVE-2007-6375
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also rep...
Bitweaver Bitweaver 1.3.1
Bitweaver Bitweaver
Bitweaver Bitweaver 1.1.1 Beta
Bitweaver Bitweaver 1.2.1
Bitweaver Bitweaver 1.3
1 EDB exploit
7.5
CVSSv2
CVE-2007-3323
SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote malicious users to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.
Comersus Open Technologies Comersus Cart 7.07
1 EDB exploit
7.5
CVSSv2
CVE-2006-6816
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote malicious users to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Ad...
Dmxready Dmxready Secure Login Manager 1.0
4 EDB exploits
6.8
CVSSv2
CVE-2007-0567
Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote malicious users to inject arbitrary web script or HTML via the _p parameter.
Interactive-scripts.com Php Membership Manager 1.5
1 EDB exploit
6.8
CVSSv2
CVE-2007-0302
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.
Instantasp Instantasp 4.1.0
2 EDB exploits
5
CVSSv2
CVE-2007-5011
webbatch.exe in WebBatch allows remote malicious users to obtain sensitive information via the dumpinputdata parameter.
Wilson Windowware Webbatch
1 EDB exploit
4.3
CVSSv2
CVE-2008-5225
Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default U...
Xerox Docushare 5
Xerox Docushare 5.00.00.2
Xerox Docushare 6.00.00.1
Xerox Docushare 6.0.1
Xerox Docushare 4
Xerox Docushare
Xerox Docushare 6.0
3 EDB exploits
4.3
CVSSv2
CVE-2008-4742
Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote malicious users to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters.
Timetrex Timetrex 2.2.11
1 EDB exploit
4.3
CVSSv2
CVE-2008-1304
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php...
Wordpress Wordpress 2.3.2
2 EDB exploits
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »