Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
post affiliate pro vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2005-3909
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and previous versions allows remote malicious users to execute arbitrary SQL commands via the sortorder parameter.
Post Affiliate Pro Post Affiliate Pro
1 EDB exploit
5
CVSSv2
CVE-2005-3910
merchants/index.php in Post Affiliate Pro 2.0.4 and previous versions, with magic_quotes_gpc disabled, allows remote malicious users to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.
Post Affiliate Pro Post Affiliate Pro 2.0.4
6.8
CVSSv2
CVE-2008-5630
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote malicious users to execute arbitrary SQL commands via the umprof_status parameter.
Qualityunit Post Affiliate Pro 3.0
Qualityunit Post Affiliate Pro 3.1.4
1 EDB exploit
NA
CVE-2023-38482
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QualityUnit Post Affiliate Pro plugin <= 1.25.0 versions.
Qualityunit Post Affiliate Pro
6.5
CVSSv2
CVE-2008-4602
Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. (dot dot) in the md parameter.
Qualityunit Post Affiliate Pro 2.0
1 EDB exploit
4
CVSSv2
CVE-2012-3802
Unspecified vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote authenticated users to read the commissions of other users via unknown attack vectors.
Peter Pokrivcak Post Affiliate Pro -
4.3
CVSSv2
CVE-2012-2706
Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote malicious users to inject arbitrary web script or HTML via vectors related to user registration.
Peter Pokrivcak Post Affiliate Pro -
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started