« Volver al listado

Webidsupport

Webidsupport Webid: vulnerabilidades y CVE

Webidsupport Webid tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-35409Crítica (9.8)0.51%—22 may 2024
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
CVE-2024-32166Alta (8.8)0.74%—19 abr 2024
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
CVE-2023-47397Crítica (9.8)0.96%—8 nov 2023
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
CVE-2022-41477Crítica (9.1)1.2%—14 oct 2022
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across…
CVE-2020-23359Crítica (9.8)1.2%—27 ene 2021
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the…
CVE-2019-11592Media (6.1)0.83%—29 abr 2019
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
CVE-2018-1000882Alta (7.5)2.4%—20 dic 2018
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This…
CVE-2018-1000868Media (6.1)1.6%—20 dic 2018
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup…
CVE-2018-1000867Alta (8.8)1.5%—20 dic 2018
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via…
CVE-2014-5114Alta (7.5)2.1%—29 jul 2014
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
CVE-2014-5101Media (4.3)2.5%—25 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6)…
CVE-2010-4873Media (4.3)1.8%—7 oct 2011
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2011-3815Media (5)1.9%—24 sept 2011
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other…
CVE-2008-7119Alta (7.5)0.97%—28 ago 2009
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-7118Media (5)2.4%—28 ago 2009
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
CVE-2008-7117Media (5)1.7%—28 ago 2009
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be…
CVE-2008-7116Alta (7.5)0.97%—28 ago 2009
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.