Skip to content
Noroxi

webidsupport records

17 published records for vendor webidsupport.

All records

17 records
  • WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden

    CriticalCVSS 9.8No exploitEPSS 1%

    webidsupport · webidJan 27, 2021

  • WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    webidsupport · webidNov 8, 2023

  • WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    webidsupport · webidMay 22, 2024

  • A security issue was discovered in WeBid <=1.2.2.

    CriticalCVSS 9.1No exploitEPSS 1%

    webidsupport · webidOct 14, 2022

  • WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da

    HighCVSS 8.8No exploitEPSS 1%

    webidsupport · webidDec 20, 2018

  • Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an

    HighCVSS 8.8No exploitEPSS 1%

    webidsupport · webidApr 19, 2024

  • WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi

    HighCVSS 7.5No exploitEPSS 2%

    webidsupport · webidDec 20, 2018

  • CVE-2014-5114
    31Monitor

    WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.

    HighCVSS 7.5No exploitEPSS 2%

    webidsupport · webidJul 29, 2014

  • CVE-2008-7116
    30Monitor

    SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma

    HighCVSS 7.5Proof of conceptEPSS 1%

    webidsupport · webidAug 28, 2009

  • CVE-2008-7119
    30Monitor

    SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p

    HighCVSS 7.5Proof of conceptEPSS 1%

    webidsupport · webidAug 28, 2009

  • WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul

    MediumCVSS 6.1No exploitEPSS 2%

    webidsupport · webidDec 20, 2018

  • WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/

    MediumCVSS 6.1No exploitEPSS 1%

    webidsupport · webidApr 29, 2019

  • CVE-2008-7118
    21Monitor

    WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t

    MediumCVSS 5.0Proof of conceptEPSS 2%

    webidsupport · webidAug 28, 2009

  • CVE-2011-3815
    21Monitor

    WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path

    MediumCVSS 5.0No exploitEPSS 2%

    webidsupport · webidSep 23, 2011

  • CVE-2008-7117
    21Monitor

    eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ

    MediumCVSS 5.0Proof of conceptEPSS 2%

    webidsupport · webidAug 28, 2009

  • CVE-2014-5101
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)

    MediumCVSS 4.3Proof of conceptEPSS 3%

    webidsupport · webidJul 25, 2014

  • CVE-2010-4873
    18Monitor

    Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 2%

    webidsupport · webidOct 7, 2011