webidsupport records
17 published records for vendor webidsupport.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-697 Incorrect Comparison1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-23359No exploit | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Critical9.8 | — | 1.2% | Jan 27, 2021 |
39Monitor | CVE-2023-47397No exploit | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.webidsupport · webid · CWE-94 | Critical9.8 | — | 1.0% | Nov 8, 2023 |
39Monitor | CVE-2024-35409No exploit | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.webidsupport · webid · CWE-89 | Critical9.8 | — | 0.5% | May 22, 2024 |
36Monitor | CVE-2022-41477No exploit | A security issue was discovered in WeBid <=1.2.2.webidsupport · webid · CWE-918 | Critical9.1 | — | 1.2% | Oct 14, 2022 |
35Monitor | CVE-2018-1000867No exploit | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Dawebidsupport · webid · CWE-89 | High8.8 | — | 1.5% | Dec 20, 2018 |
35Monitor | CVE-2024-32166No exploit | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now anwebidsupport · webid · CWE-639 | High8.8 | — | 0.7% | Apr 19, 2024 |
31Monitor | CVE-2018-1000882No exploit | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fiwebidsupport · webid · CWE-22 | High7.5 | — | 2.4% | Dec 20, 2018 |
31Monitor | CVE-2014-5114No exploit | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.webidsupport · webid | High7.5 | — | 2.1% | Jul 29, 2014 |
30Monitor | CVE-2008-7116Proof of concept | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commawebidsupport · webid · CWE-89 | High7.5 | — | 1.0% | Aug 28, 2009 |
30Monitor | CVE-2008-7119Proof of concept | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id pwebidsupport · webid · CWE-89 | High7.5 | — | 1.0% | Aug 28, 2009 |
24Monitor | CVE-2018-1000868No exploit | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resulwebidsupport · webid · CWE-79 | Medium6.1 | — | 1.6% | Dec 20, 2018 |
24Monitor | CVE-2019-11592No exploit | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/webidsupport · webid · CWE-79 | Medium6.1 | — | 0.8% | Apr 29, 2019 |
21Monitor | CVE-2008-7118Proof of concept | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers twebidsupport · webid · CWE-264 | Medium5.0 | — | 2.4% | Aug 28, 2009 |
21Monitor | CVE-2011-3815No exploit | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pathwebidsupport · webid · CWE-200 | Medium5.0 | — | 1.9% | Sep 23, 2011 |
21Monitor | CVE-2008-7117Proof of concept | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requwebidsupport · webid · CWE-264 | Medium5.0 | — | 1.7% | Aug 28, 2009 |
18Monitor | CVE-2014-5101Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)webidsupport · webid · CWE-79 | Medium4.3 | — | 2.5% | Jul 25, 2014 |
18Monitor | CVE-2010-4873Proof of concept | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML viawebidsupport · webid · CWE-79 | Medium4.3 | — | 1.8% | Oct 7, 2011 |
- CVE-2020-2335939Monitor
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
CriticalCVSS 9.8No exploitEPSS 1%webidsupport · webidJan 27, 2021
- CVE-2023-4739739Monitor
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
CriticalCVSS 9.8No exploitEPSS 1%webidsupport · webidNov 8, 2023
- CVE-2024-3540939Monitor
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
CriticalCVSS 9.8No exploitEPSS 1%webidsupport · webidMay 22, 2024
- CVE-2022-4147736Monitor
A security issue was discovered in WeBid <=1.2.2.
CriticalCVSS 9.1No exploitEPSS 1%webidsupport · webidOct 14, 2022
- CVE-2018-100086735Monitor
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da
HighCVSS 8.8No exploitEPSS 1%webidsupport · webidDec 20, 2018
- CVE-2024-3216635Monitor
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an
HighCVSS 8.8No exploitEPSS 1%webidsupport · webidApr 19, 2024
- CVE-2018-100088231Monitor
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi
HighCVSS 7.5No exploitEPSS 2%webidsupport · webidDec 20, 2018
- CVE-2014-511431Monitor
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
HighCVSS 7.5No exploitEPSS 2%webidsupport · webidJul 29, 2014
- CVE-2008-711630Monitor
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 1%webidsupport · webidAug 28, 2009
- CVE-2008-711930Monitor
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p
HighCVSS 7.5Proof of conceptEPSS 1%webidsupport · webidAug 28, 2009
- CVE-2018-100086824Monitor
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul
MediumCVSS 6.1No exploitEPSS 2%webidsupport · webidDec 20, 2018
- CVE-2019-1159224Monitor
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/
MediumCVSS 6.1No exploitEPSS 1%webidsupport · webidApr 29, 2019
- CVE-2008-711821Monitor
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t
MediumCVSS 5.0Proof of conceptEPSS 2%webidsupport · webidAug 28, 2009
- CVE-2011-381521Monitor
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
MediumCVSS 5.0No exploitEPSS 2%webidsupport · webidSep 23, 2011
- CVE-2008-711721Monitor
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ
MediumCVSS 5.0Proof of conceptEPSS 2%webidsupport · webidAug 28, 2009
- CVE-2014-510118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)
MediumCVSS 4.3Proof of conceptEPSS 3%webidsupport · webidJul 25, 2014
- CVE-2010-487318Monitor
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3Proof of conceptEPSS 2%webidsupport · webidOct 7, 2011