Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
high-tech bridge sa vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-4607
Multiple cross-site scripting (XSS) vulnerabilities in Habari 0.6.5, when register_globals is enabled, allow remote malicious users to inject arbitrary web script or HTML via the (1) additem_form parameter to system/admin/dash_additem.php and the (2) status_data[] parameter to sy...
Habariproject Habari 0.6.5
1 EDB exploit
NA
CVE-2010-4608
Habari 0.6.5 allows remote malicious users to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admin/, which reveals the installation path in an error message.
Habariproject Habari 0.6.5
1 EDB exploit
NA
CVE-2010-4612
Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) user_name and (2) usr_email parameters to user/1/hregister.html, (3) usr_email parameter to user/1...
Hycus Hycus Cms 1.0.3
1 EDB exploit
NA
CVE-2010-2463
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom prior to 4.1.9 allows remote malicious users to inject arbitrary web script or HTML via the post_id parameter in a modify action.
Jamroom Jamroom 1.0
Jamroom Jamroom 3.4.0
Jamroom Jamroom 2.66
Jamroom Jamroom 2.65
Jamroom Jamroom 2.67
Jamroom Jamroom 3.0
Jamroom Jamroom 3.3.4
Jamroom Jamroom 3.3.3
Jamroom Jamroom 3.0.5
Jamroom Jamroom 3.0.12
Jamroom Jamroom 3.0.11
Jamroom Jamroom 3.0.10
Jamroom Jamroom 3.0.22
Jamroom Jamroom 3.0.23
Jamroom Jamroom 3.0.24
Jamroom Jamroom 3.0.25
Jamroom Jamroom 4.1.5
Jamroom Jamroom 4.1.4
Jamroom Jamroom 4.1.3
Jamroom Jamroom 4.1.2
Jamroom Jamroom 4.0.4
Jamroom Jamroom 4.0.3
1 EDB exploit
NA
CVE-2010-2856
Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote malicious users to inject arbitrary web script or HTML via the page parameter.
Oscss Oscss
Oscss Oscss 1.2.1
Oscss Oscss 1.0.1
Oscss Oscss 1.0
Oscss Oscss 1.2
Oscss Oscss 1.1
Oscss Oscss 1.2.2
1 EDB exploit
NA
CVE-2011-5259
SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM prior to 2.6.11.2 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Orangehrm Orangehrm 2.6.5
Orangehrm Orangehrm 2.6.4
Orangehrm Orangehrm 2.6.10
Orangehrm Orangehrm 2.6.3
Orangehrm Orangehrm 2.6.2
Orangehrm Orangehrm 2.6.8
Orangehrm Orangehrm 2.6.7
Orangehrm Orangehrm 2.6.6
Orangehrm Orangehrm 2.6.0.1
Orangehrm Orangehrm
Orangehrm Orangehrm 2.6.9
Orangehrm Orangehrm 2.6.8.1
Orangehrm Orangehrm 2.6.1
Orangehrm Orangehrm 2.6.0
1 EDB exploit
6.1
CVSSv3
CVE-2011-4336
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
Tiki Tikiwiki Cms\\/groupware
1 EDB exploit
NA
CVE-2010-1997
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.
Saurus Saurus Cms 4.7.0
1 EDB exploit
NA
CVE-2010-2038
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from t...
Gpeasy Gpeasy Cms 1.6.2
1 EDB exploit
NA
CVE-2013-3081
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo prior to 1.2.2 allows remote malicious users to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/.
Jojocms Jojo-cms
Jojocms Jojo-cms 1.2
Jojocms Jojo-cms 1.1
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »