Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dynpg dynpg vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote malicious users to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are o...
Dynpg Dynpg 4.2.0
Dynpg Dynpg 4.1.1
1 EDB exploit
520
VMScore
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.ph...
Dynpg Dynpg
2 EDB exploits
312
VMScore
CVE-2020-27406
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated malicious users to execute arbitrary code via the groupname.
Dynpg Dynpg 4.9.1
755
VMScore
CVE-2010-4400
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote malicious users to execute arbitrary SQL commands via the giveRights_UserId parameter.
Dynpg Dynpg 4.2.0
1 EDB exploit
505
VMScore
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote malicious users to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Dynpg Dynpg 4.2.0
1 EDB exploit
312
VMScore
CVE-2021-27526
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "page" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27527
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "valueID" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27528
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "refID" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27529
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "limit" parameter.
Dynpg Dynpg 4.9.2
312
VMScore
CVE-2021-27530
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote malicious user to inject javascript via URI in /index.php.
Dynpg Dynpg 4.9.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
remote code execution
CVE-2024-34909
CVE-2024-3317
SSTI
CVE-2024-3400
CVE-2024-30051
wireless
CVE-2024-4622
CVE-2024-4908
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »