Skip to content
Noroxi

webspell records

21 published records for vendor webspell.

All records

21 records
  • webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability

    CriticalCVSS 10.0No exploitEPSS 3%

    webspell · webspellMar 2, 2007

  • CVE-2007-4028
    30Monitor

    Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files

    HighCVSS 7.5No exploitEPSS 2%

    webspell · webspellJul 26, 2007

  • CVE-2010-4861
    30Monitor

    SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parame

    HighCVSS 7.5Proof of conceptEPSS 1%

    webspell · webspellOct 5, 2011

  • CVE-2006-0728
    30Monitor

    SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the t

    HighCVSS 7.5Proof of conceptEPSS 1%

    webspell · webspellFeb 16, 2006

  • CVE-2007-0502
    30Monitor

    SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID param

    HighCVSS 7.5Proof of conceptEPSS 1%

    webspell · webspellJan 25, 2007

  • CVE-2006-5388
    30Monitor

    SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the g

    HighCVSS 7.5Proof of conceptEPSS 1%

    webspell · webspellOct 18, 2006

  • CVE-2007-1163
    30Monitor

    SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via t

    HighCVSS 7.5Proof of conceptEPSS 1%

    webspell · webspellMar 2, 2007

  • CVE-2007-0492
    30Monitor

    Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL comman

    HighCVSS 7.5No exploitEPSS 1%

    webspell · webspellJan 24, 2007

  • CVE-2009-1912
    28Monitor

    Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arb

    MediumCVSS 6.8Proof of conceptEPSS 3%

    webspell · webspellJun 4, 2009

  • CVE-2007-1019
    27Monitor

    SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary

    MediumCVSS 6.8Proof of conceptEPSS 1%

    webspell · webspellFeb 21, 2007

  • CVE-2007-1154
    27Monitor

    SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerab

    MediumCVSS 6.8No exploitEPSS 1%

    webspell · webspellMar 2, 2007

  • CVE-2007-2369
    23Monitor

    Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to

    MediumCVSS 5.0Proof of conceptEPSS 8%

    php · phpApr 30, 2007

  • CVE-2006-4782
    22Monitor

    src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain s

    MediumCVSS 5.4Proof of conceptEPSS 3%

    webspell · webspellSep 14, 2006

  • CVE-2007-2368
    21Monitor

    picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.

    MediumCVSS 5.0Proof of conceptEPSS 2%

    webspell · webspellApr 30, 2007

  • CVE-2006-4783
    20Monitor

    SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to exec

    MediumCVSS 5.1No exploitEPSS 1%

    webspell · webspellSep 14, 2006

  • CVE-2007-6309
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3Proof of conceptEPSS 4%

    webspell · webspellDec 11, 2007

  • CVE-2009-1408
    18Monitor

    Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote att

    MediumCVSS 4.3Proof of conceptEPSS 2%

    webspell · webspellApr 24, 2009

  • CVE-2007-1155
    18Monitor

    Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via t

    MediumCVSS 4.6No exploitEPSS 1%

    webspell · webspellMar 2, 2007

  • CVE-2008-0574
    17Monitor

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 2%

    webspell · webspellFeb 4, 2008

  • CVE-2008-1481
    17Monitor

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via t

    MediumCVSS 4.3Proof of conceptEPSS 1%

    webspell · webspellMar 24, 2008

  • CVE-2008-0575
    17Monitor

    Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmi

    MediumCVSS 4.3No exploitEPSS 1%

    webspell · webspellFeb 4, 2008