Opendocman

Opendocman · 14 CVEs

CVE-2019-25684
HIGH

OpenDocMan 1.3.4 SQL Injection via where Parameter

Apr 5, 2026

CVE-2021-45834
CRITICAL

An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypas…

Mar 18, 2022

CVE-2014-1946
HIGH

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to byp…

Apr 10, 2018

CVE-2015-5625
MEDIUM

Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web scr…

Sep 7, 2015

CVE-2014-4853
MEDIUM

Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users…

Jul 10, 2014

CVE-2014-2317
MEDIUM

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary S…

Mar 7, 2014

CVE-2014-1945
HIGH

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary S…

Mar 7, 2014

CVE-2011-3764
MEDIUM

OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php…

Sep 24, 2011

CVE-2009-3801
HIGH

SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands…

Oct 27, 2009

CVE-2009-3789
MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web…

Oct 26, 2009

CVE-2009-3788
HIGH

SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands…

Oct 26, 2009

CVE-2008-2788
MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary w…

Jun 20, 2008

CVE-2008-2787
MEDIUM

Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web…

Jun 20, 2008

CVE-2006-5655
HIGH

SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands…

Nov 3, 2006

Showing 1 to 14 of 14 CVEs