Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webapp HIGH 7.5
CVE-2007-3419

The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.d…

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp HIGH 7.5
CVE-2007-3420

The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the …

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp HIGH 7.5
CVE-2007-3421

The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedb…

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp HIGH 7.5
CVE-2007-3422

The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing cha…

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp HIGH 7.5
CVE-2007-3423

cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file na…

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp HIGH 7.5
CVE-2007-3424

The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when mo…

Fix: after 0.9.9.6
Fix from $1,950 2007-06-26
Webapp MEDIUM 6.5
CVE-2007-3418

The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real…

Fix: after 0.9.9.6
Fix from $1,600 2007-06-26
Webapp MEDIUM 5.0
CVE-2007-3416

Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-a…

Fix: after 0.9.9.6
Fix from $1,600 2007-06-26
Webapp MEDIUM 6.0
CVE-2007-1827

Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data f…

Patch available
Fix from $1,600 2007-04-03
Webapp MEDIUM 6.0
CVE-2007-1831

web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.

Patch available
Fix from $1,600 2007-04-03
Webapp MEDIUM 5.0
CVE-2007-1832

web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percent encod…

Fix: after 0.9.9.5
Fix from $1,600 2007-04-03
Webapp MEDIUM 6.8
CVE-2007-1489

Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modi…

Patch available
Fix from $1,600 2007-03-16
Webapp HIGH 7.5
CVE-2007-1259

Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.

Patch available
Fix from $1,950 2007-03-03
Webapp HIGH 7.5
CVE-2007-1178

WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) …

Fix: after 0.9.9.4
Fix from $1,950 2007-03-02
Webapp HIGH 7.5
CVE-2007-1183

WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors.

Fix: after 0.9.9.4
Fix from $1,950 2007-03-02
Webapp HIGH 7.5
CVE-2007-1188

WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown im…

Patch available
Fix from $1,950 2007-03-02
Webapp MEDIUM 6.4
CVE-2007-1182

WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.8
CVE-2007-1177

WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon …

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.5
CVE-2007-1187

WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature …

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.0
CVE-2007-1179

WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders a…

Fix: after 0.9.9.4
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.0
CVE-2007-1181

WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.0
CVE-2007-1184

The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.0
CVE-2007-1185

The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and…

Patch available
Fix from $1,600 2007-03-02
Webapp MEDIUM 5.0
CVE-2007-1186

WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.

Patch available
Fix from $1,600 2007-03-02
Webapp HIGH 7.5
CVE-2005-1628EPSS 11%

apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f…

No fix yet
Fix from $1,950 2005-05-17
Webapp HIGH 10.0
CVE-2005-0927

Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .…

Patch available
Fix from $1,950 2005-05-02
Webapp MEDIUM 5.0
CVE-2004-1742EPSS 7%

Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.

Patch available
Fix from $1,600 2004-08-24