Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dynpg vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote malicious users to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are o...
Dynpg Dynpg 4.2.0
Dynpg Dynpg 4.1.1
1 EDB exploit
5.1
CVSSv2
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.ph...
Dynpg Dynpg
2 EDB exploits
3.5
CVSSv2
CVE-2021-27527
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "valueID" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27530
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote malicious user to inject javascript via URI in /index.php.
Dynpg Dynpg 4.9.2
5
CVSSv2
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote malicious users to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Dynpg Dynpg 4.2.0
1 EDB exploit
7.5
CVSSv2
CVE-2010-4400
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote malicious users to execute arbitrary SQL commands via the giveRights_UserId parameter.
Dynpg Dynpg 4.2.0
1 EDB exploit
3.5
CVSSv2
CVE-2021-27528
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "refID" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27526
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "page" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27529
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "limit" parameter.
Dynpg Dynpg 4.9.2
3.5
CVSSv2
CVE-2021-27531
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote malicious users to inject JavaScript via the "query" parameter.
Dynpg Dynpg 4.9.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »