Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webid CRITICAL 9.8
CVE-2024-35409

WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

No fix yet
Fix from $2,300 2024-05-22
Webid HIGH 8.8
CVE-2024-32166

Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction …

No fix yet
Fix from $1,950 2024-04-19
Webid CRITICAL 9.8
CVE-2023-47397

WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

Fix: after 1.2.2
Fix from $2,300 2023-11-08
Webid CRITICAL 9.1
CVE-2022-41477

A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attack…

Fix: after 1.2.2
Fix from $2,300 2022-10-14
Webid CRITICAL 9.8
CVE-2020-23359

WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness…

No fix yet
Fix from $2,300 2021-01-27
Webid MEDIUM 6.1
CVE-2019-11592

WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeus…

No fix yet
Fix from $1,600 2019-04-29
Webid HIGH 7.5
CVE-2018-1000882

WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. …

Fix: after 1.2.2
Fix from $1,950 2018-12-20
Webid HIGH 8.8
CVE-2018-1000867

WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Re…

Fix: after 1.2.2
Fix from $1,950 2018-12-20
Webid MEDIUM 6.1
CVE-2018-1000868

WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Java…

Fix: after 1.2.2
Fix from $1,600 2018-12-20
Webid HIGH 7.5
CVE-2014-5114

WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.

No fix yet
Fix from $1,950 2014-07-29
Webid MEDIUM 5.0
CVE-2011-3815

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

Mitigation only
Fix from $1,600 2011-09-24
Webid HIGH 7.5
CVE-2008-7116

SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via t…

No fix yet
Fix from $1,950 2009-08-28
Webid HIGH 7.5
CVE-2008-7119

SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

No fix yet
Fix from $1,950 2009-08-28
Webid MEDIUM 5.0
CVE-2008-7117

eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with …

No fix yet
Fix from $1,600 2009-08-28
Webid MEDIUM 5.0
CVE-2008-7118

WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain …

No fix yet
Fix from $1,600 2009-08-28