Lucene search

K

Max's Guestbook Security Vulnerabilities

securityvulns
securityvulns

CatBot v0.4.2 (PHP) - SQL Injection Vulnerability

Document Title: CatBot v0.4.2 (PHP) - SQL Injection Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1408 Release Date: 2015-01-15 Vulnerability Laboratory ID (VL-ID): 1408 Common Vulnerability Scoring System: 7.3 Product & Service Introduction: CatBot is a...

0.1AI Score

2015-01-19 12:00 AM
18
packetstorm

0.4AI Score

2015-01-19 12:00 AM
35
zdt
zdt

CatBot 0.4.2 SQL Injection Vulnerability

CatBot version 0.4.2 suffers from a remote SQL injection...

8.1AI Score

2015-01-17 12:00 AM
18
vulnerlab

0.3AI Score

2015-01-16 12:00 AM
15
packetstorm

-0.3AI Score

2015-01-16 12:00 AM
16
vulnerlab

7.1AI Score

2015-01-16 12:00 AM
16
vulnerlab

0.2AI Score

2015-01-15 12:00 AM
10
vulnerlab

7.1AI Score

2015-01-15 12:00 AM
9
seebug
seebug

用友香港官网存在注入导致帐号密码泄漏

简要描述: 注入点:www.yonyou.com.hk/new/download_view.php?uid=4 详细说明: 2.数据库:db1007112_ufida中39个表 Database: db1007112_ufida [39 tables] +-------------------------+ | admin_log | | adpic | | app_cat | | app_company | | app_file | |...

7.2AI Score

2015-01-14 12:00 AM
13
openbugbounty
openbugbounty

lorente.ch Open Redirect vulnerability

Open Bug Bounty ID: OBB-53326 Description| Value ---|--- Affected Website:| lorente.ch Open Bug Bounty Program:| Create your bounty program now. It's open and free. Vulnerable Application:| Custom Code Vulnerability Type:| Open Redirect / CWE-601 CVSSv3 Score:| 3.4...

6.7AI Score

2015-01-10 07:29 PM
8
securityvulns
securityvulns

Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks,...

1.6AI Score

EPSS

2014-12-29 12:00 AM
23
securityvulns
securityvulns

Lazarus Guestbook v1.22 - Multiple Web Vulnerabilities

Document Title: Lazarus Guestbook v1.22 - Multiple Web Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1386 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-2239 CVE-ID: CVE-2014-2239 Release Date: 2014-12-24 Vulnerability Laboratory ID (VL-ID):...

-0.1AI Score

EPSS

2014-12-29 12:00 AM
102
zdt
zdt

Lazarus Guestbook v1.22 - Multiple Web Vulnerabilities

Exploit for php platform in category web...

6.5AI Score

EPSS

2014-12-27 12:00 AM
23
packetstorm

0.2AI Score

EPSS

2014-12-26 12:00 AM
17
vulnerlab

6.5AI Score

EPSS

2014-12-24 12:00 AM
6
exploitpack
exploitpack

Lazarus Guestbook 1.22 - Multiple Vulnerabilities

Lazarus Guestbook 1.22 - Multiple...

0.5AI Score

EPSS

2014-12-24 12:00 AM
16
exploitdb

6.7AI Score

EPSS

2014-12-24 12:00 AM
15
vulnerlab

6.5AI Score

EPSS

2014-12-24 12:00 AM
12
securityvulns
securityvulns

Persistent XSS Vulnerability in CMS Papoo Light v6.0.0 Rev. 4701

Advisory: Persistent XSS Vulnerability in CMS Papoo Light v6 Advisory ID: SROEADV-2014-01 Author: Steffen Rцsemann Affected Software: CMS Papoo Version 6.0.0 Rev. 4701 Vendor URL: http://www.papoo.de/ Vendor Status: fixed CVE-ID: - ========================== Vulnerability Description:...

-0.1AI Score

2014-12-22 12:00 AM
94
zdt
zdt

Papoo CMS 6.0.0 Rev. 4701 - Stored XSS Vulnerability

Exploit for php platform in category web...

7.1AI Score

2014-12-18 12:00 AM
9
exploitpack
exploitpack

CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site Scripting

CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site...

-0.5AI Score

2014-12-16 12:00 AM
7
exploitdb

7.4AI Score

EPSS

2014-12-16 12:00 AM
12
packetstorm

0.2AI Score

2014-12-15 12:00 AM
12
packetstorm

-0.1AI Score

2014-12-12 12:00 AM
71
seebug
seebug

大米CMS多处XSS盲打后台

简要描述: 大米CMS多处XSS盲打后台 详细说明: 大米CMS多处XSS可以盲打后台,大米CMS后台的SQL注入一大堆,只要进了后台获取数据不成问题 第一处 文件/Web/Lib/Action/GuestbookAction.class.php public function update() { //输出gb2312码,ajax默认转的是utf-8 header("Content-type: text/html; charset=utf-8"); if(!isset($_POST['author']) or...

7AI Score

2014-11-01 12:00 AM
19
zdt
zdt

XAMPP 1.8.x Multiple Vulnerabilities

Exploit for multiple platform in category remote...

7.1AI Score

2014-10-06 12:00 AM
826
seebug
seebug

cmseasy csrf通过一个xss最后getshell

简要描述: 为什么我们要选择get类型的呢,因为get类型存储到数据库的时候触发时候管理员是察觉不到的,可以通过图片等进行操作,然后我们存储一个xss后门,这样一来,我们就可以加载一个远端的js,那么就各种无视token和referer了 详细说明: 开始我们先分析一段源代码: celive/admin/system.php:(line:128-142): `` if($do == 'add' and $username != '') { $password = addslashes($_REQUEST['password']); $password =...

7AI Score

2014-09-04 12:00 AM
15
seebug
seebug

DouPHP SQL注入一枚

简要描述: 注入 详细说明: 依然是get_ip的问题, guestbook.php:102行 ``` if ($rec == 'insert') { / 跨站请求伪造CSRF的防御 / if ($firewall->check_token($_POST['token'])) { / html安全过滤器 / $_POST = $firewall->dou_filter($_POST); $ip = $dou->get_ip(); $add_time = time(); $vcode =...

7.1AI Score

2014-07-04 12:00 AM
37
seebug

7.1AI Score

2014-07-01 12:00 AM
8
seebug

7.1AI Score

2014-07-01 12:00 AM
8
seebug
seebug

PHPKIT 1.6 - Multiple Input Validation Vulnerabilities

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
13
seebug

7.1AI Score

2014-07-01 12:00 AM
14
seebug

7.1AI Score

2014-07-01 12:00 AM
12
seebug
seebug

Angora Guestbook 1.5 - Local File Inclusion

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
15
seebug

7.1AI Score

2014-07-01 12:00 AM
6
seebug

7.1AI Score

2014-07-01 12:00 AM
12
seebug
seebug

GuppY 2.4 HTML Injection Vulnerability

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
10
seebug

7.1AI Score

2014-07-01 12:00 AM
13
seebug
seebug

gaestebuch 1.2 - Remote File Inclusion Vulnerability

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
19
seebug

7.1AI Score

2014-07-01 12:00 AM
11
seebug

7.1AI Score

2014-07-01 12:00 AM
9
seebug
seebug

gBook 1.4 Administrative Access Vulnerability

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
7
seebug

7.1AI Score

2014-07-01 12:00 AM
7
seebug

7.1AI Score

2014-07-01 12:00 AM
17
seebug

7.1AI Score

2014-07-01 12:00 AM
8
seebug

7.1AI Score

2014-07-01 12:00 AM
15
seebug

7.1AI Score

2014-07-01 12:00 AM
21
seebug
seebug

phpGB 1.1 HTML Injection Vulnerability

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
5
seebug

7.1AI Score

2014-07-01 12:00 AM
10
seebug
seebug

FTLS GuestBook 1.1 Script Injection Vulnerability

No description provided by...

7.1AI Score

2014-07-01 12:00 AM
8
Total number of security vulnerabilities2444