Перейти к содержимому
Noroxi

Записи webidsupport

17 опубликованных записей вендора webidsupport.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

17 записей
  • CVE-2020-23359
    39Наблюдать

    WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webidsupport · webid27 янв. 2021 г.

  • CVE-2023-47397
    39Наблюдать

    WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webidsupport · webid8 нояб. 2023 г.

  • CVE-2024-35409
    39Наблюдать

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webidsupport · webid22 мая 2024 г.

  • CVE-2022-41477
    36Наблюдать

    A security issue was discovered in WeBid <=1.2.2.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    webidsupport · webid14 окт. 2022 г.

  • CVE-2018-1000867
    35Наблюдать

    WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webidsupport · webid20 дек. 2018 г.

  • CVE-2024-32166
    35Наблюдать

    Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webidsupport · webid19 апр. 2024 г.

  • CVE-2018-1000882
    31Наблюдать

    WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    webidsupport · webid20 дек. 2018 г.

  • CVE-2014-5114
    31Наблюдать

    WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    webidsupport · webid29 июл. 2014 г.

  • CVE-2008-7116
    30Наблюдать

    SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webidsupport · webid28 авг. 2009 г.

  • CVE-2008-7119
    30Наблюдать

    SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webidsupport · webid28 авг. 2009 г.

  • CVE-2018-1000868
    24Наблюдать

    WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    webidsupport · webid20 дек. 2018 г.

  • CVE-2019-11592
    24Наблюдать

    WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    webidsupport · webid29 апр. 2019 г.

  • CVE-2008-7118
    21Наблюдать

    WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t

    СредняяCVSS 5,0Proof of conceptEPSS 2 %

    webidsupport · webid28 авг. 2009 г.

  • CVE-2011-3815
    21Наблюдать

    WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    webidsupport · webid23 сент. 2011 г.

  • CVE-2008-7117
    21Наблюдать

    eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ

    СредняяCVSS 5,0Proof of conceptEPSS 2 %

    webidsupport · webid28 авг. 2009 г.

  • CVE-2014-5101
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    webidsupport · webid25 июл. 2014 г.

  • CVE-2010-4873
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    webidsupport · webid7 окт. 2011 г.