Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
r3d-d3v!l vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-7192
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.
Etoshop Dynamic Biz Website Builder Quickweb 1.0
2 EDB exploits
NA
CVE-2011-0645
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote malicious users to execute arbitrary SQL commands via the where_time parameter in a get action.
Phpcms Phpcms 2008 2
2 EDB exploits
NA
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote malicious users to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.
Etoshop C2c Forward Auction Creator 2.0
2 EDB exploits
NA
CVE-2008-6809
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote malicious users to execute arbitrary SQL commands via the HotelID parameter.
Bookingcentre Booking System For Hotels Group 2.01
2 EDB exploits
NA
CVE-2008-5974
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) password and (2) username fields.
Activewebsoftwares Active Price Comparison 4.0
2 EDB exploits
NA
CVE-2009-3175
Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote malicious users to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id param...
Boldfx Model Agency Manager Pro -
1 EDB exploit
NA
CVE-2009-3343
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote malicious users to execute arbitrary SQL commands via the PropId parameter.
Hotwebscripts Hotweb Rentals
1 EDB exploit
NA
CVE-2010-5047
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote malicious users to execute arbitrary SQL commands via the id parameter.
V-eva Press Release Script
1 EDB exploit
NA
CVE-2011-0644
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote malicious users to execute arbitrary SQL commands via the modelid parameter to flash_upload.php.
Phpcms Phpcms 2008 2
1 EDB exploit
NA
CVE-2008-7083
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote malicious users to execute arbitrary SQL commands via the (1) username and (2) password fields.
Revou Micro Blogging Twitter Clone
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »