İçeriğe atla
Noroxi

webidsupport kayıtları

webidsupport üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2020-23359
    39İzleyin

    WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden

    KritikCVSS 9,8İstismar yokEPSS %1

    webidsupport · webid27 Oca 2021

  • CVE-2023-47397
    39İzleyin

    WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    webidsupport · webid8 Kas 2023

  • CVE-2024-35409
    39İzleyin

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    webidsupport · webid22 May 2024

  • CVE-2022-41477
    36İzleyin

    A security issue was discovered in WeBid <=1.2.2.

    KritikCVSS 9,1İstismar yokEPSS %1

    webidsupport · webid14 Eki 2022

  • WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da

    YüksekCVSS 8,8İstismar yokEPSS %1

    webidsupport · webid20 Ara 2018

  • CVE-2024-32166
    35İzleyin

    Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an

    YüksekCVSS 8,8İstismar yokEPSS %1

    webidsupport · webid19 Nis 2024

  • WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi

    YüksekCVSS 7,5İstismar yokEPSS %2

    webidsupport · webid20 Ara 2018

  • CVE-2014-5114
    31İzleyin

    WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.

    YüksekCVSS 7,5İstismar yokEPSS %2

    webidsupport · webid29 Tem 2014

  • CVE-2008-7116
    30İzleyin

    SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    webidsupport · webid28 Ağu 2009

  • CVE-2008-7119
    30İzleyin

    SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    webidsupport · webid28 Ağu 2009

  • WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul

    OrtaCVSS 6,1İstismar yokEPSS %2

    webidsupport · webid20 Ara 2018

  • CVE-2019-11592
    24İzleyin

    WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/

    OrtaCVSS 6,1İstismar yokEPSS %1

    webidsupport · webid29 Nis 2019

  • CVE-2008-7118
    21İzleyin

    WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t

    OrtaCVSS 5,0Kavram kanıtıEPSS %2

    webidsupport · webid28 Ağu 2009

  • CVE-2011-3815
    21İzleyin

    WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path

    OrtaCVSS 5,0İstismar yokEPSS %2

    webidsupport · webid23 Eyl 2011

  • CVE-2008-7117
    21İzleyin

    eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ

    OrtaCVSS 5,0Kavram kanıtıEPSS %2

    webidsupport · webid28 Ağu 2009

  • CVE-2014-5101
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)

    OrtaCVSS 4,3Kavram kanıtıEPSS %3

    webidsupport · webid25 Tem 2014

  • CVE-2010-4873
    18İzleyin

    Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    webidsupport · webid7 Eki 2011