Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opendocman HIGH 8.2
CVE-2019-25684

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t…

Fix: after 1.3.4
Fix from $1,950 2026-04-05
Opendocman CRITICAL 9.8
CVE-2021-45834

An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically …

Mitigation only
Fix from $2,300 2022-03-18
Opendocman HIGH 8.8
CVE-2014-1946

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restric…

Fix: after 1.2.7
Fix from $1,950 2018-04-10
Opendocman HIGH 7.5
CVE-2014-1945

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value …

Fix: after 1.2.7.1
Fix from $1,950 2014-03-09
Opendocman MEDIUM 6.8
CVE-2014-2317

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table para…

Fix: after 1.2.7.1
Fix from $1,600 2014-03-09
Opendocman MEDIUM 5.0
CVE-2011-3764

OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the instal…

No fix yet
Fix from $1,600 2011-09-24
Opendocman HIGH 7.5
CVE-2009-3801

SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password)…

Mitigation only
Fix from $1,950 2009-10-27
Opendocman HIGH 7.5
CVE-2009-3788

SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username)…

Patch available
Fix from $1,950 2009-10-26
Opendocman HIGH 7.5
CVE-2006-5655

SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Mitigation only
Fix from $1,950 2006-11-03