Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
egix vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 up to and including 5.2.0 allows remote malicious users to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config ...
Cubecart Cubecart
1 EDB exploit
NA
CVE-2013-3528
Unspecified vulnerability in the update check in Vanilla Forums prior to 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."
Vanillaforums Vanilla 2.0.18.4
Vanillaforums Vanilla 2.0.18.3
Vanillaforums Vanilla 2.0.18
Vanillaforums Vanilla 2.0.17.10
Vanillaforums Vanilla 2.0.17.8
Vanillaforums Vanilla 2.0.14
Vanillaforums Vanilla 2.0.13
Vanillaforums Vanilla 2.0.5
Vanillaforums Vanilla 2.0.4
Vanillaforums Vanilla 2.0.18.6
Vanillaforums Vanilla 2.0.18.5
Vanillaforums Vanilla 2.0.17.1
Vanillaforums Vanilla 2.0.17
Vanillaforums Vanilla 2.0.16.1
Vanillaforums Vanilla 2.0.15
Vanillaforums Vanilla 2.0.7
Vanillaforums Vanilla 2.0.6
Vanillaforums Vanilla
Vanillaforums Vanilla 2.0.17.2
Vanillaforums Vanilla 2.0.17.3
Vanillaforums Vanilla 2.0.17.7
Vanillaforums Vanilla 2.0.16
1 EDB exploit
9.8
CVSSv3
CVE-2014-3990
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and previous versions allows remote malicious users to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted ser...
Opencart Opencart
NA
CVE-2011-4337
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 up to and including 3.65 allows remote malicious users to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.
Sitracker Support Incident Tracker 3.6
Sitracker Support Incident Tracker 3.60
Sitracker Support Incident Tracker 3.61
Sitracker Support Incident Tracker 3.62
Sitracker Support Incident Tracker 3.45
Sitracker Support Incident Tracker 3.50
Sitracker Support Incident Tracker 3.64
Sitracker Support Incident Tracker 3.63
Sitracker Support Incident Tracker 3.51
Sitracker Support Incident Tracker 3.65
1 EDB exploit
NA
CVE-2007-5453
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php,...
Php-stats Php-stats 0.1.9.2
1 EDB exploit
NA
CVE-2008-6632
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and previous versions allows remote malicious users to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
Mercuryboard Mercuryboard 1.1.2
Mercuryboard Mercuryboard 1.1.1
Mercuryboard Mercuryboard 1.1
Mercuryboard Mercuryboard 1.0
Mercuryboard Mercuryboard
1 EDB exploit
NA
CVE-2014-5297
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 up to and including 4.1.7 allows remote malicious users to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter.
X2engine X2engine 4.1.7
X2engine X2engine 2.8
NA
CVE-2007-4053
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the order parameter to new_images.php.
Linpha Linpha
1 EDB exploit
NA
CVE-2008-4645
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and previous versions allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Phpwebgallery Phpwebgallery 1.4.1
Phpwebgallery Phpwebgallery 1.1
Phpwebgallery Phpwebgallery 1.5.0
Phpwebgallery Phpwebgallery 1.6.0
Phpwebgallery Phpwebgallery 1.6.2
Phpwebgallery Phpwebgallery 1.3.4
Phpwebgallery Phpwebgallery 1.6.1
Phpwebgallery Phpwebgallery 1.3.2
Phpwebgallery Phpwebgallery 1.3.3
Phpwebgallery Phpwebgallery 1.5.2
Phpwebgallery Phpwebgallery 1.5.1
Phpwebgallery Phpwebgallery 1.3.0
Phpwebgallery Phpwebgallery 1.4.0
Phpwebgallery Phpwebgallery 1.7.0
Phpwebgallery Phpwebgallery 1.0
Phpwebgallery Phpwebgallery 1.2.1
Phpwebgallery Phpwebgallery 1.3.1
Phpwebgallery Phpwebgallery
Phpwebgallery Phpwebgallery 1.7.1
1 EDB exploit
6.1
CVSSv3
CVE-2015-7711
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the h parameter.
Atutor Atutor
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »