Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
websvn websvn vulnerabilities and exploits
(subscribe to this query)
9.3
CVSSv2
CVE-2011-2195
A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operati...
Websvn Websvn 2.3.2
10
CVSSv2
CVE-2021-32305
WebSVN prior to 2.6.1 allows remote malicious users to execute arbitrary commands via shell metacharacters in the search parameter.
Websvn Websvn
4.3
CVSSv2
CVE-2016-1236
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent malicious users to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.
Websvn Websvn
Debian Debian Linux 8.0
4.3
CVSSv2
CVE-2016-2511
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the path parameter to log.php.
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Websvn Websvn
3.5
CVSSv2
CVE-2013-6892
WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.
Websvn Websvn 2.3.3
Debian Debian Linux 7.0
4.3
CVSSv2
CVE-2011-5221
Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN prior to 2.3.1 allows remote malicious users to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.
Websvn Websvn 2.2.0
Websvn Websvn 2.1.0
Websvn Websvn
Websvn Websvn 2.2.1
Websvn Websvn 2.0
Websvn Websvn 1.61
3.5
CVSSv2
CVE-2009-0240
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
Tigris Websvn 2.0
4.3
CVSSv2
CVE-2008-5918
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO.
Tigris Websvn 1.38
Tigris Websvn 1.37
Tigris Websvn 1.04
Tigris Websvn 1.03
Tigris Websvn
Tigris Websvn 1.60
Tigris Websvn 1.61
Tigris Websvn 1.34
Tigris Websvn 1.33
Tigris Websvn 1.02
Tigris Websvn 1.01
Tigris Websvn 1.62
Tigris Websvn 1.51
Tigris Websvn 1.32
Tigris Websvn 1.31a
Tigris Websvn 1.00
Tigris Websvn 1.40
Tigris Websvn 1.39
Tigris Websvn 1.20
Tigris Websvn 1.10
1 EDB exploit
6.8
CVSSv2
CVE-2008-5919
Directory traversal vulnerability in rss.php in WebSVN 2.0 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to overwrite arbitrary files via directory traversal sequences in the rev parameter.
Tigris Websvn 1.61
Tigris Websvn 1.62
Tigris Websvn 1.51
Tigris Websvn 1.32
Tigris Websvn 1.31a
Tigris Websvn 1.00
Tigris Websvn 1.40
Tigris Websvn 1.39
Tigris Websvn 1.20
Tigris Websvn 1.10
Tigris Websvn 1.38
Tigris Websvn 1.37
Tigris Websvn 1.04
Tigris Websvn 1.03
Tigris Websvn
Tigris Websvn 1.60
Tigris Websvn 1.34
Tigris Websvn 1.33
Tigris Websvn 1.02
Tigris Websvn 1.01
1 EDB exploit
7.5
CVSSv2
CVE-2008-5920
The create_anchors function in utils.inc in WebSVN 1.x allows remote malicious users to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch.
Tigris Websvn 1.37
Tigris Websvn 1.34
Tigris Websvn 1.03
Tigris Websvn 1.02
Tigris Websvn 1.60
Tigris Websvn 1.61
Tigris Websvn 1.33
Tigris Websvn 1.32
Tigris Websvn 1.01
Tigris Websvn 1.00
Tigris Websvn 1.62
Tigris Websvn 1.51
Tigris Websvn 1.31a
Tigris Websvn 1.20
Tigris Websvn 1.40
Tigris Websvn 1.39
Tigris Websvn 1.38
Tigris Websvn 1.10
Tigris Websvn 1.04
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »