Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
rgod vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-4191
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and previous versions allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP se...
Xmb Software Extreme Message Board
1 EDB exploit
NA
CVE-2006-4267
Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and the (2) x_invoice_num parameter in modules/gateway/Authorize/confirm...
Devellion Cubecart 3.0.7-pl1
Devellion Cubecart 3.0.6
Devellion Cubecart 3.0.7
Devellion Cubecart 3.0.3
Devellion Cubecart 3.0.4
Devellion Cubecart 3.0.11
1 EDB exploit
NA
CVE-2012-2052
Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x prior to 12.0.5 and CS5.1 12.1.x prior to 12.1.1 allows remote malicious users to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value i...
Adobe Photoshop Cs5.1 12.1
Adobe Photoshop Cs5 12.0
Adobe Photoshop Cs5 12.0.2
Adobe Photoshop Cs5 12.0.4
Adobe Photoshop Cs5 12.0.1
Adobe Photoshop Cs5 12.0.3
1 EDB exploit
NA
CVE-2005-3390
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote malicious users to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS&...
Php Php 3.0.14
Php Php 3.0.15
Php Php 3.0.5
Php Php 3.0.6
Php Php 4.0.2
Php Php 4.0.3
Php Php 4.0.7
Php Php 4.2.3
Php Php 4.2
Php Php 4.3.5
Php Php 4.3.6
Php Php 5.0.2
Php Php 5.0.3
Php Php 3.0
Php Php 3.0.1
Php Php 3.0.16
Php Php 3.0.17
Php Php 3.0.7
Php Php 3.0.8
Php Php 4.0.4
Php Php 4.1.0
Php Php 4.1.1
1 EDB exploit
NA
CVE-2005-3738
globals.php in Mambo Site Server 4.0.14 and previous versions, when register_globals is disabled, allows remote malicious users to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php...
Mambo Mambo Site Server 4.0.12 Rc1
Mambo Mambo Site Server 4.0.12 Rc2
Mambo Mambo Site Server 4.0.11
Mambo Mambo Site Server 4.0.12
Mambo Mambo Site Server 4.0
Mambo Mambo Site Server 4.0.10
Mambo Mambo Site Server 4.0.12 Rc3
Mambo Mambo Site Server 4.0.14
Mambo Mambo Site Server 4.0.12 Beta
Mambo Mambo Site Server 4.0.12 Beta 2
1 EDB exploit
NA
CVE-2005-3811
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and previous versions allows remote malicious users to overwrite arbitrary files with session information via the sid parameter.
Amax Information Technologies Magic Winmail Server
1 EDB exploit
NA
CVE-2006-1784
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and previous versions, when register_globals is disabled, allows remote malicious users to execute arbitrary PHP code via a URL in the settings_dir parameter.
Sphider Sphider 1.3
Sphider Sphider 1.3 Rc1
Sphider Sphider 1.3 Rc2
1 EDB exploit
NA
CVE-2005-2885
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote malicious users to bypass file extension checks and execute arbitrary commands by uploading a file with a diffe...
Maxdev Md-pro 1.0.73
1 EDB exploit
NA
CVE-2005-2954
SQL injection vulnerability in password_reminder.php in ATutor prior to 1.5.1 pl1 allows remote malicious users to execute arbitrary SQL commands via the email field.
Adaptive Technology Resource Centre Atutor 1.5.1
1 EDB exploit
NA
CVE-2005-3045
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote malicious users to execute arbitrary SQL commands via the phrase field.
My Little Homepage My Little Forum 1.3
My Little Homepage My Little Forum 1.5
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
hardcoded
arbitrary code
CVE-2024-2404
CVE-2024-21111
CVE-2024-28627
CVE-2024-4073
information disclosure
CVE-2024-32780
CVE-2024-4040
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »