Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webopac MEDIUM 5.4
CVE-2024-11021

Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript …

Fix: 6.5.1 / 7.2.3+
Fix from $1,600 2024-11-11
Webopac CRITICAL 9.8
CVE-2024-11020

Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, mod…

Fix: 6.5.1 / 7.2.3+
Fix from $2,300 2024-11-11
Webopac CRITICAL 9.8
CVE-2024-11018

Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshell…

Fix: 6.5.1 / 7.2.3+
Fix from $2,300 2024-11-11
Webopac MEDIUM 6.1
CVE-2024-11019

Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Fix: 6.5.1 / 7.2.3+
Fix from $1,600 2024-11-11
Webopac CRITICAL 9.8
CVE-2024-11016

Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, mod…

Fix: 6.5.1 / 7.2.3+
Fix from $2,300 2024-11-11
Webopac HIGH 8.8
CVE-2024-11017

Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute …

Fix: 6.5.1 / 7.2.3+
Fix from $1,950 2024-11-11
Webopac HIGH 8.8
CVE-2021-42839

Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attacke…

Mitigation only
Fix from $1,950 2021-11-15
Webopac MEDIUM 6.1
CVE-2021-42838

Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers c…

Mitigation only
Fix from $1,600 2021-11-15
Vice HIGH 7.2
CVE-2004-0453

Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash)…

Patch available
Fix from $1,950 2004-08-06