Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kingoftheworld vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2008-0233
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and previous versions allows remote malicious users to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
Zero Cms Zero Cms 1.0 Alpha
1 EDB exploit
7.5
CVSSv2
CVE-2008-0232
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.
Zero Cms Zero Cms 1.0 Alpha
1 EDB exploit
7.5
CVSSv2
CVE-2007-6396
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and previous versions allows remote malicious users to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by ac...
Myupb Flat Php Board 1.2
1 EDB exploit
7.5
CVSSv2
CVE-2007-6366
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and previous versions allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_ad...
Sinecms Sinecms
1 EDB exploit
7.5
CVSSv2
CVE-2007-6292
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and previous versions allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Mwopen E-commerce 0
Mwopen E-commerce 1.4
1 EDB exploit
7.5
CVSSv2
CVE-2007-6185
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter in a download action, as demonstrated by a certain PHP file containing database credentials.
Eurologon Eurologon Cms
1 EDB exploit
7.5
CVSSv2
CVE-2007-6164
Multiple SQL injection vulnerabilities in Eurologon CMS allow remote malicious users to execute arbitrary SQL commands via the id parameter to (1) reviews.php, (2) links.php and (3) articles.php.
Eurologon Eurologon Cms
1 EDB exploit
7.5
CVSSv2
CVE-2007-6159
SQL injection vulnerability in index.php in Tilde CMS 4.x and previous versions allows remote malicious users to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.
Tilde Tilde Cms 4.0
1 EDB exploit
7.5
CVSSv2
CVE-2007-5822
Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and previous versions allows remote malicious users to inject arbitrary PHP code into a certain file in regged/ via the username parameter in a Register action, possibly related to the register function ...
Scribe Scribe 0.2
1 EDB exploit
7.5
CVSSv2
CVE-2007-5823
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and previous versions allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) in the username parameter in a Register action.
Scribe Scribe 0.2
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »