Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webspell webspell 4.01.02 vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2007-4028
Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote malicious users to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information.
Webspell Webspell 4.01.02
685
VMScore
CVE-2007-1019
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote malicious users to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.
Webspell Webspell 4.01.02
1 EDB exploit
435
VMScore
CVE-2008-0574
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote malicious users to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.
Webspell Webspell 4.01.02
1 EDB exploit
383
VMScore
CVE-2008-0575
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote malicious users to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action.
Webspell Webspell 4.01.02
755
VMScore
CVE-2007-0502
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote malicious users to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.
Webspell Webspell 4.01.02
1 EDB exploit
685
VMScore
CVE-2009-1912
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and previous versions allows remote malicious users to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including ...
Webspell Webspell
Webspell Webspell 4.1.2
Webspell Webspell 4.1.1
Webspell Webspell 4.2.0c
Webspell Webspell 4.2.0d
Webspell Webspell 4.0.2c
Webspell Webspell 4.0
Webspell Webspell 4.01.01
Webspell Webspell 4.01.00
Webspell Webspell 4.1
Webspell Webspell 4.01.02
1 EDB exploit
755
VMScore
CVE-2007-1163
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.
Webspell Webspell
Webspell Webspell 4.0
Webspell Webspell 4.01.00
Webspell Webspell 4.01.01
1 EDB exploit
505
VMScore
CVE-2007-2368
picture.php in WebSPELL 4.01.02 and previous versions allows remote malicious users to read arbitrary files via the file parameter.
Webspell Webspell
1 EDB exploit
505
VMScore
CVE-2007-2369
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and previous versions, when PHP prior to 4.3.0 is used, allows remote malicious users to read arbitrary files via a .. (dot dot) in the id parameter.
Php Php
Webspell Webspell
1 EDB exploit
668
VMScore
CVE-2007-0492
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The provenance of this information is unknown; the details are obtained ...
Webspell Webspell
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started