Opendocman
Opendocman · 14 CVEs
OpenDocMan 1.3.4 SQL Injection via where Parameter
Apr 5, 2026
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypas…
Mar 18, 2022
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to byp…
Apr 10, 2018
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web scr…
Sep 7, 2015
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users…
Jul 10, 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary S…
Mar 7, 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary S…
Mar 7, 2014
OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php…
Sep 24, 2011
SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands…
Oct 27, 2009
Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web…
Oct 26, 2009
SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands…
Oct 26, 2009
Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary w…
Jun 20, 2008
Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web…
Jun 20, 2008
SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands…
Nov 3, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-25684 | OpenDocMan 1.3.4 SQL Injection via where Parameter | HIGH | 0.33% | Apr 5, 2026 |
| CVE-2021-45834 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed… | CRITICAL | 2.31% | Mar 18, 2022 |
| CVE-2014-1946 | OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and… | HIGH | 2.48% | Apr 10, 2018 |
| CVE-2015-5625 | Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection paramete… | MEDIUM | 22.79% | Sep 7, 2015 |
| CVE-2014-4853 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML… | MEDIUM | 1.94% | Jul 10, 2014 |
| CVE-2014-2317 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOT… | MEDIUM | 1.16% | Mar 7, 2014 |
| CVE-2014-1945 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter. | HIGH | 1.30% | Mar 7, 2014 |
| CVE-2011-3764 | OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat… | MEDIUM | 1.35% | Sep 24, 2011 |
| CVE-2009-3801 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter… | HIGH | 1.01% | Oct 27, 2009 |
| CVE-2009-3789 | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message para… | MEDIUM | 2.81% | Oct 26, 2009 |
| CVE-2009-3788 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter. | HIGH | 1.21% | Oct 26, 2009 |
| CVE-2008-2788 | Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection pa… | MEDIUM | 0.84% | Jun 20, 2008 |
| CVE-2008-2787 | Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message par… | MEDIUM | 1.83% | Jun 20, 2008 |
| CVE-2006-5655 | SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | HIGH | 1.19% | Nov 3, 2006 |
Showing 1 to 14 of 14 CVEs