Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2019-25684 OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t… Opendocman after 1.3.4 Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2021-45834 An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically … Opendocman Mitigation only Fix from $2,3002022-03-18 HIGH 8.8 CVE-2014-1946 OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restric… Opendocman after 1.2.7 Fix from $1,9502018-04-10 HIGH 7.5 CVE-2014-1945 SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value … Opendocman after 1.2.7.1 Fix from $1,9502014-03-09 MEDIUM 6.8 CVE-2014-2317 SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table para… Opendocman after 1.2.7.1 Fix from $1,6002014-03-09 MEDIUM 5.0 CVE-2011-3764 OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the instal… Opendocman No fix yet Fix from $1,6002011-09-24 HIGH 7.5 CVE-2009-3801 SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password)… Opendocman Mitigation only Fix from $1,9502009-10-27 HIGH 7.5 CVE-2009-3788 SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username)… Opendocman Patch available Fix from $1,9502009-10-26 HIGH 7.5 CVE-2006-5655 SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter. Opendocman Mitigation only Fix from $1,9502006-11-03