Lucene search

K

Website Security Vulnerabilities

cve
cve

CVE-2006-6214

SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid...

8.8AI Score

0.006EPSS

2006-12-01 01:28 AM
19
cve
cve

CVE-2006-6220

Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to execute arbitrary SQL commands via the (1) recipeid parameter to recipe.php or the (2) categoryid parameter to...

8.9AI Score

0.007EPSS

2006-12-01 01:28 AM
18
cve
cve

CVE-2006-5636

PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR...

8AI Score

0.058EPSS

2006-11-01 12:07 AM
20
cve
cve

CVE-2006-5258

The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is...

8.1AI Score

0.086EPSS

2006-10-12 10:07 PM
15
cve
cve

CVE-2006-2307

Cross-site scripting (XSS) vulnerability in Website Baker CMS before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a user display...

5.5AI Score

0.004EPSS

2006-05-11 10:02 AM
23
cve
cve

CVE-2006-0936

Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing...

7AI Score

0.014EPSS

2006-02-28 11:02 AM
20
cve
cve

CVE-2005-4372

Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page...

6AI Score

0.007EPSS

2005-12-20 02:03 AM
22
cve
cve

CVE-2005-4373

Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error...

7AI Score

0.006EPSS

2005-12-20 02:03 AM
19
cve
cve

CVE-2005-4140

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user...

8.4AI Score

0.037EPSS

2005-12-09 03:03 PM
31
cve
cve

CVE-2005-3860

PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir...

7.9AI Score

0.104EPSS

2005-11-29 11:03 AM
27
cve
cve

CVE-2005-2435

Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir...

6AI Score

0.007EPSS

2005-08-03 04:00 AM
23
cve
cve

CVE-2005-2436

browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error...

6.4AI Score

0.01EPSS

2005-08-03 04:00 AM
27
cve
cve

CVE-2005-2437

Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP...

7.9AI Score

0.011EPSS

2005-08-03 04:00 AM
20
cve
cve

CVE-2004-1841

SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP...

8.6AI Score

0.002EPSS

2005-05-10 04:00 AM
19
cve
cve

CVE-2003-0456

VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using...

6.5AI Score

0.006EPSS

2003-08-18 04:00 AM
55
cve
cve

CVE-2001-0394

Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn...

7AI Score

0.008EPSS

2002-03-09 05:00 AM
28
cve
cve

CVE-2001-0626

O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":"...

6.9AI Score

0.031EPSS

2002-03-09 05:00 AM
27
cve
cve

CVE-1999-1180

O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2)...

7.7AI Score

0.002EPSS

2001-09-12 04:00 AM
22
cve
cve

CVE-2000-0622

Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords"...

7.8AI Score

0.024EPSS

2001-05-07 04:00 AM
21
cve
cve

CVE-2000-0769

O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling...

7.8AI Score

0.004EPSS

2000-10-20 04:00 AM
20
cve
cve

CVE-2000-0623

Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer...

7.9AI Score

0.002EPSS

2000-08-03 04:00 AM
27
cve
cve

CVE-2000-0066

WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL...

6.6AI Score

0.005EPSS

2000-02-04 05:00 AM
34
4
Total number of security vulnerabilities272