Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
egix vulnerabilities and exploits
(subscribe to this query)
5.1
CVSSv2
CVE-2008-1856
plugins/maps/db_handler.php in LinPHA 1.3.3 and previous versions does not require authentication for a settings action that modifies the configuration file, which allows remote malicious users to conduct directory traversal attacks and execute arbitrary local files by placing di...
Linpha Linpha 0.9.1
Linpha Linpha 0.9.2
Linpha Linpha 0.9.3
Linpha Linpha 1.1.1
Linpha Linpha 1.2.0
Linpha Linpha 0.9.4
Linpha Linpha 1.0
Linpha Linpha 1.3.0
Linpha Linpha 1.3.1
Linpha Linpha 1.3.2
Linpha Linpha
Linpha Linpha 0.9.0
Linpha Linpha 1.1.0
1 EDB exploit
5
CVSSv2
CVE-2014-8790
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 up to and including 3.3.x prior to 3.3.5 Beta 1, when in certain configurations, allows remote malicious users to read arbitrary files via the data parameter.
Get-simple Getsimple Cms 3.3.2
Get-simple Getsimple Cms 3.2
Cagintranetworks Getsimple Cms 3.3.3
Cagintranetworks Getsimple Cms 3.3.4
Get-simple Getsimple Cms 3.1.1
Get-simple Getsimple Cms 3.1.2
Get-simple Getsimple Cms 3.2.1
Get-simple Getsimple Cms 3.2.2
Get-simple Getsimple Cms 3.3.0
Get-simple Getsimple Cms 3.2.3
Get-simple Getsimple Cms 3.3.1
5
CVSSv2
CVE-2016-2212
The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition prior to 1.14.2.3 and Magento Community Edition prior to 1.9.2.3 allows remote malicious users to obtain sensitive order information via...
Magento Magento
6.8
CVSSv2
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin prior to 1.2 for WordPress allows remote malicious users to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a direct request to the fi...
Kishore Asokan Kish Guest Posting Plugin
Kishore Asokan Kish Guest Posting Plugin 1.0
1 EDB exploit
7.5
CVSSv2
CVE-2007-6550
form.php in PMOS Help Desk 2.4 and previous versions sends a redirect to the web browser but does not exit, which allows remote malicious users to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
Pmos Helpdesk Pmos Helpdesk
1 EDB exploit
5
CVSSv2
CVE-2011-5147
Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and previous versions allows remote malicious users to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a c...
Freewebshop Freewebshop 2.2.6
Freewebshop Freewebshop 2.2.5
Freewebshop Freewebshop
Freewebshop Freewebshop 2.2.9
Freewebshop Freewebshop 2.2.2
Freewebshop Freewebshop 2.2.1
Freewebshop Freewebshop 2.1
Freewebshop Freewebshop 2.2.3
Freewebshop Freewebshop 2.2.4
Freewebshop Freewebshop 2.2.7 Wip1 2
Freewebshop Freewebshop 2.2.7
1 EDB exploit
9.3
CVSSv2
CVE-2008-4453
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote malicious users to create, overwrite, and modify arbitrary f...
Dspicture Light Imaging Toolkit 4.7.1
Dspicture Pro Imaging Sdk 5.7.1
1 EDB exploit
9
CVSSv2
CVE-2008-4645
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and previous versions allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Phpwebgallery Phpwebgallery 1.4.1
Phpwebgallery Phpwebgallery 1.1
Phpwebgallery Phpwebgallery 1.5.0
Phpwebgallery Phpwebgallery 1.6.0
Phpwebgallery Phpwebgallery 1.6.2
Phpwebgallery Phpwebgallery 1.3.4
Phpwebgallery Phpwebgallery 1.6.1
Phpwebgallery Phpwebgallery 1.3.2
Phpwebgallery Phpwebgallery 1.3.3
Phpwebgallery Phpwebgallery 1.5.2
Phpwebgallery Phpwebgallery 1.5.1
Phpwebgallery Phpwebgallery 1.3.0
Phpwebgallery Phpwebgallery 1.4.0
Phpwebgallery Phpwebgallery 1.7.0
Phpwebgallery Phpwebgallery 1.0
Phpwebgallery Phpwebgallery 1.2.1
Phpwebgallery Phpwebgallery 1.3.1
Phpwebgallery Phpwebgallery
Phpwebgallery Phpwebgallery 1.7.1
1 EDB exploit
7.5
CVSSv2
CVE-2008-6475
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and previous versions allows remote malicious users to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
Drake Team Drake Cms
Drake Team Drake Cms 0.2
1 EDB exploit
7.5
CVSSv2
CVE-2008-6490
function/update_xml.php in FLABER 1.1 and previous versions allows remote malicious users to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using f...
Flysforum Flaber
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »