Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bitweaver MEDIUM 6.1
CVE-2012-5193

Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via …

Fix: after 2.8.1
Fix from $1,600 2019-11-13
Bitweaver MEDIUM 5.0
CVE-2012-5192EPSS 52%

Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F"…

Fix: after 2.8.1
Fix from $1,600 2014-01-28
Bitweaver MEDIUM 5.0
CVE-2010-5086

Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) …

No fix yet
Fix from $1,600 2012-03-19
Bitweaver HIGH 7.5
CVE-2009-1678

Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to creat…

Fix: after 2.6
Fix from $1,950 2009-05-18
Bitweaver MEDIUM 6.5
CVE-2009-1677

Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote au…

Fix: after 2.6
Fix from $1,600 2009-05-18
R2 Cms HIGH 7.5
CVE-2007-6650

Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image…

No fix yet
Fix from $1,950 2008-01-04
Bitweaver MEDIUM 5.0
CVE-2007-6651

Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) v…

No fix yet
Fix from $1,600 2008-01-04
Bitweaver MEDIUM 6.8
CVE-2007-6412

Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackers to in…

Fix: after 2.0.0
Fix from $1,600 2007-12-17
Bitweaver HIGH 7.5
CVE-2007-6375

Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode …

Fix: after 2.0.0
Fix from $1,950 2007-12-15
Bitweaver HIGH 7.5
CVE-2006-6923

SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via t…

No fix yet
Fix from $1,950 2007-01-13
Bitweaver MEDIUM 6.8
CVE-2006-6925

Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via …

No fix yet
Fix from $1,600 2007-01-13
Bitweaver MEDIUM 5.0
CVE-2006-6924

bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2)…

No fix yet
Fix from $1,600 2007-01-13
Bitweaver MEDIUM 5.1
CVE-2006-3102EPSS 8%

Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitr…

Patch available
Fix from $1,600 2006-06-21
Bitweaver MEDIUM 5.0
CVE-2006-3104EPSS 9%

users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the instal…

No fix yet
Fix from $1,600 2006-06-21
Bitweaver MEDIUM 5.0
CVE-2006-3105

CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple un…

No fix yet
Fix from $1,600 2006-06-21
Bitweaver HIGH 7.5
CVE-2005-4380

Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode…

Mitigation only
Fix from $1,950 2005-12-20