Webidsupport
Webidsupport Webid: vulnerabilidades y CVE
Webidsupport Webid tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-35409 | Crítica (9.8) | 0.51% | — | 22 may 2024 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. |
| CVE-2024-32166 | Alta (8.8) | 0.74% | — | 19 abr 2024 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation). |
| CVE-2023-47397 | Crítica (9.8) | 0.96% | — | 8 nov 2023 | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. |
| CVE-2022-41477 | Crítica (9.1) | 1.2% | — | 14 oct 2022 | A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across… |
| CVE-2020-23359 | Crítica (9.8) | 1.2% | — | 27 ene 2021 | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the… |
| CVE-2019-11592 | Media (6.1) | 0.83% | — | 29 abr 2019 | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php. |
| CVE-2018-1000882 | Alta (7.5) | 2.4% | — | 20 dic 2018 | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This… |
| CVE-2018-1000868 | Media (6.1) | 1.6% | — | 20 dic 2018 | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup… |
| CVE-2018-1000867 | Alta (8.8) | 1.5% | — | 20 dic 2018 | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via… |
| CVE-2014-5114 | Alta (7.5) | 2.1% | — | 29 jul 2014 | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. |
| CVE-2014-5101 | Media (4.3) | 2.5% | — | 25 jul 2014 | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6)… |
| CVE-2010-4873 | Media (4.3) | 1.8% | — | 7 oct 2011 | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. |
| CVE-2011-3815 | Media (5) | 1.9% | — | 24 sept 2011 | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other… |
| CVE-2008-7119 | Alta (7.5) | 0.97% | — | 28 ago 2009 | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. |
| CVE-2008-7118 | Media (5) | 2.4% | — | 28 ago 2009 | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. |
| CVE-2008-7117 | Media (5) | 1.7% | — | 28 ago 2009 | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be… |
| CVE-2008-7116 | Alta (7.5) | 0.97% | — | 28 ago 2009 | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username. |