Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-35409 WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. Webid No fix yet Fix from $2,3002024-05-22 HIGH 8.8 CVE-2024-32166 Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction … Webid No fix yet Fix from $1,9502024-04-19 CRITICAL 9.8 CVE-2023-47397 WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. Webid after 1.2.2 Fix from $2,3002023-11-08 CRITICAL 9.1 CVE-2022-41477 A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attack… Webid after 1.2.2 Fix from $2,3002022-10-14 CRITICAL 9.8 CVE-2020-23359 WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness… Webid No fix yet Fix from $2,3002021-01-27 MEDIUM 6.1 CVE-2019-11592 WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeus… Webid No fix yet Fix from $1,6002019-04-29 HIGH 7.5 CVE-2018-1000882 WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. … Webid after 1.2.2 Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-1000867 WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Re… Webid after 1.2.2 Fix from $1,9502018-12-20 MEDIUM 6.1 CVE-2018-1000868 WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Java… Webid after 1.2.2 Fix from $1,6002018-12-20 HIGH 7.5 CVE-2014-5114 WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. Webid No fix yet Fix from $1,9502014-07-29 MEDIUM 5.0 CVE-2011-3815 WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er… Webid Mitigation only Fix from $1,6002011-09-24 HIGH 7.5 CVE-2008-7116 SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via t… Webid No fix yet Fix from $1,9502009-08-28 HIGH 7.5 CVE-2008-7119 SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. Webid No fix yet Fix from $1,9502009-08-28 MEDIUM 5.0 CVE-2008-7117 eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with … Webid No fix yet Fix from $1,6002009-08-28 MEDIUM 5.0 CVE-2008-7118 WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain … Webid No fix yet Fix from $1,6002009-08-28