web-app.org records
36 published records for vendor web-app.org.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-16 Configuration1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2005-0927No exploit | Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacweb-app.org · webapp | Critical10.0 | — | 1.6% | May 2, 2005 |
33Monitor | CVE-2005-1628Proof of concept | apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharactersweb-app.org · webapp · CWE-20 | High7.5 | — | 10.6% | May 17, 2005 |
31Monitor | CVE-2007-3242No exploit | The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allowsweb-app.net · webapp · CWE-264 | High7.5 | — | 2.1% | Jun 14, 2007 |
30Monitor | CVE-2007-1188No exploit | WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has uweb-app.org · webapp | High7.5 | — | 1.5% | Mar 2, 2007 |
30Monitor | CVE-2007-1183No exploit | WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attacweb-app.org · webapp | High7.5 | — | 1.5% | Mar 2, 2007 |
30Monitor | CVE-2007-1178No exploit | WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,web-app.org · webapp | High7.5 | — | 1.4% | Mar 2, 2007 |
30Monitor | CVE-2007-1259No exploit | Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.web-app.org · webapp | High7.5 | — | 1.2% | Mar 3, 2007 |
30Monitor | CVE-2007-3424No exploit | The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory namweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
30Monitor | CVE-2007-3419No exploit | The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) laweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
30Monitor | CVE-2007-3420No exploit | The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not cweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
30Monitor | CVE-2007-3421No exploit | The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
30Monitor | CVE-2007-3422No exploit | The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-priweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
30Monitor | CVE-2007-3423No exploit | cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .daweb-app.org · webapp | High7.5 | — | 1.1% | Jun 26, 2007 |
27Monitor | CVE-2007-1489No exploit | Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin accesweb-app.org · webapp · CWE-352 | Medium6.8 | — | 0.7% | Mar 16, 2007 |
26Monitor | CVE-2007-3418No exploit | The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction web-app.org · webapp | Medium6.5 | — | 1.1% | Jun 26, 2007 |
25Monitor | CVE-2007-1827No exploit | Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corruweb-app.org · webapp | Medium6.0 | — | 1.9% | Apr 2, 2007 |
25Monitor | CVE-2007-1182No exploit | WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.web-app.org · webapp | Medium6.4 | — | 1.1% | Mar 2, 2007 |
24Monitor | CVE-2007-1831No exploit | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.web-app.org · webapp | Medium6.0 | — | 1.1% | Apr 2, 2007 |
23Monitor | CVE-2007-1177No exploit | WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Pweb-app.org · webapp | Medium5.8 | — | 1.1% | Mar 2, 2007 |
22Monitor | CVE-2004-1742Proof of concept | Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..web-app.org · webapp | Medium5.0 | — | 7.2% | Aug 24, 2004 |
22Monitor | CVE-2007-1187No exploit | WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archiveweb-app.org · webapp | Medium5.5 | — | 1.2% | Mar 2, 2007 |
20Monitor | CVE-2007-1832No exploit | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percweb-app.org · webapp | Medium5.0 | — | 1.2% | Apr 2, 2007 |
20Monitor | CVE-2007-1181No exploit | WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack veweb-app.org · webapp | Medium5.0 | — | 1.1% | Mar 2, 2007 |
20Monitor | CVE-2007-1186No exploit | WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.web-app.org · webapp | Medium5.0 | — | 1.1% | Mar 2, 2007 |
20Monitor | CVE-2007-1185No exploit | The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown iweb-app.org · webapp | Medium5.0 | — | 1.1% | Mar 2, 2007 |
- CVE-2005-092740Plan
Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharac
CriticalCVSS 10.0No exploitEPSS 2%web-app.org · webappMay 2, 2005
- CVE-2005-162833Monitor
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters
HighCVSS 7.5Proof of conceptEPSS 11%web-app.org · webappMay 17, 2005
- CVE-2007-324231Monitor
The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows
HighCVSS 7.5No exploitEPSS 2%web-app.net · webappJun 14, 2007
- CVE-2007-118830Monitor
WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has u
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-118330Monitor
WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attac
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-117830Monitor
WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-125930Monitor
Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappMar 3, 2007
- CVE-2007-342430Monitor
The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory nam
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-341930Monitor
The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) la
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-342030Monitor
The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not c
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-342130Monitor
The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gall
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-342230Monitor
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-pri
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-342330Monitor
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .da
HighCVSS 7.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-148927Monitor
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin acces
MediumCVSS 6.8No exploitEPSS 1%web-app.org · webappMar 16, 2007
- CVE-2007-341826Monitor
The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction
MediumCVSS 6.5No exploitEPSS 1%web-app.org · webappJun 26, 2007
- CVE-2007-182725Monitor
Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corru
MediumCVSS 6.0No exploitEPSS 2%web-app.org · webappApr 2, 2007
- CVE-2007-118225Monitor
WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.
MediumCVSS 6.4No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-183124Monitor
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.
MediumCVSS 6.0No exploitEPSS 1%web-app.org · webappApr 2, 2007
- CVE-2007-117723Monitor
WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum P
MediumCVSS 5.8No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2004-174222Monitor
Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 7%web-app.org · webappAug 24, 2004
- CVE-2007-118722Monitor
WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive
MediumCVSS 5.5No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-183220Monitor
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using perc
MediumCVSS 5.0No exploitEPSS 1%web-app.org · webappApr 2, 2007
- CVE-2007-118120Monitor
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack ve
MediumCVSS 5.0No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-118620Monitor
WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
MediumCVSS 5.0No exploitEPSS 1%web-app.org · webappMar 2, 2007
- CVE-2007-118520Monitor
The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown i
MediumCVSS 5.0No exploitEPSS 1%web-app.org · webappMar 2, 2007