Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)1.0%—Xigla Absolute Banner Manager18/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute Banner Manager XE 2.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the text parameter in (1) searchbanners.asp and (2) listadvertisers.asp, and other unspecified fields. NOTE: some of these details are…
ModificadaMedia (6.5)1.2%—Xigla Absolute Banner Manager18/6/200816/6/2026
SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
ModificadaMedia (4.3)1.3%—Medialand Rotabanner Local10/1/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.
ModificadaMedia (5)1.3%—PHP Mysql Banner Exchange21/12/200716/6/2026
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.
ModificadaAlta (7.5)1.1%—Xigla Absolute Banner Manager.net10/12/200716/6/2026
SQL injection vulnerability in abm.aspx in Xigla Absolute Banner Manager .NET 4.0 allows remote attackers to execute arbitrary SQL commands via the z parameter.
ModificadaAlta (7.5)2.3%💥 ExploitJiro Banner System22/11/200716/6/2026
Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.
ModificadaMedia (6.5)0.87%💥 ExploitSoftbizscripts Banner Exchange Network Script15/11/200716/6/2026
SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.7%💥 ExploitPHP WEB Scripts Easy Banner PRO11/1/200716/6/2026
PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.
ModificadaAlta (7.5)2.5%💥 ExploitPHP WEB Scripts Easy Banner Free5/10/200616/6/2026
PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.
ModificadaMedia (6.8)2.9%💥 ExploitMambo Multibanners25/7/200616/6/2026
PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
AnalizadaMedia (4.3)1.8%💥 ExploitSoftbizscripts Banner Exchange Script18/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php,…
ModificadaMedia (5.8)1.5%—Native Solutions THE Banner Engine11/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in The Banner Engine (tbe) 4.0 allow remote attackers to execute arbitrary web script or HTML via the (1) text parameter in a search action to (a) top.php, and the (2) adminpass or (3) adminlogin parameter to (b) signup.php.
ModificadaMedia (5.1)2.1%—Eschew.net Phpbannerexchange19/6/200616/6/2026
Interpretation conflict in resetpw.php in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via an email parameter containing a null (%00) character after a valid e-mail address, which passes the validation check in the eregi PHP command. NOTE: it could be argued that this…
ModificadaAlta (7.5)1.5%—Eschew.net Phpbannerexchange19/6/200616/6/2026
SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php.
ModificadaAlta (7.5)4.0%—Duware Dubanner Project Duware Dubanner17/5/200616/6/2026
add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.
ModificadaMedia (4.3)1.9%💥 ExploitPerlcoders Group Bannerfarm20/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.
ModificadaBaja (2.6)1.8%💥 ExploitAweb Banner Generator11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.
ModificadaAlta (7.5)8.8%💥 ExploitJiro Banner System14/3/200616/6/2026
JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.
ModificadaMedia (5)2.8%—Eschew.net Phpbannerexchange14/3/200616/6/2026
Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php).
ModificadaMedia (4.3)1.2%—Native Solutions TBE Banner Engine31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.
ModificadaAlta (10)5.4%—Bannerwheel31/12/200216/6/2026
Buffer overflow in badmin.c in BannerWheel 1.0 allows remote attackers to execute arbitrary code via a long rcmd command.
ModificadaMedia (5)1.0%—JOE Depasquale Bannermatic31/12/200216/6/2026
Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient access control, which allows attackers to obtain sensitive information via a direct request for the files.
ModificadaMedia (5.1)2.4%—Selena SOL Webbanner2/2/200016/6/2026
Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Orbitaley — Vulnerabilidades