Web-App.org / Webapp
36 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-3424 | The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an in… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3423 | cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when th… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3422 | The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3421 | The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabi… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3420 | The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) userna… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3419 | The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) pr… | HIGH | 7.5 | Jun 26, 2007 |
| CVE-2007-3418 | The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, wh… | MEDIUM | 6.5 | Jun 26, 2007 |
| CVE-2007-3417 | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrar… | MEDIUM | 4.3 | Jun 26, 2007 |
| CVE-2007-3416 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org Web… | MEDIUM | 5.0 | Jun 26, 2007 |
| CVE-2007-3242 | The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticat… | HIGH | 7.5 | Jun 15, 2007 |
| CVE-2007-1832 | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percent encoding in for… | MEDIUM | 5.0 | Apr 3, 2007 |
| CVE-2007-1831 | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING. | MEDIUM | 6.0 | Apr 3, 2007 |
| CVE-2007-1830 | Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain administrative access via u… | MEDIUM | 4.3 | Apr 3, 2007 |
| CVE-2007-1828 | Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTM… | LOW | 3.5 | Apr 3, 2007 |
| CVE-2007-1827 | Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain… | MEDIUM | 6.0 | Apr 3, 2007 |
| CVE-2007-1489 | Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cook… | MEDIUM | 6.8 | Mar 16, 2007 |
| CVE-2007-1259 | Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors. | HIGH | 7.5 | Mar 3, 2007 |
| CVE-2007-1188 | WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, poss… | HIGH | 7.5 | Feb 28, 2007 |
| CVE-2007-1187 | WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Re… | MEDIUM | 5.5 | Feb 28, 2007 |
| CVE-2007-1186 | WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact. | MEDIUM | 5.0 | Feb 28, 2007 |
| CVE-2007-1185 | The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote at… | MEDIUM | 5.0 | Feb 28, 2007 |
| CVE-2007-1184 | The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data. | MEDIUM | 5.0 | Feb 28, 2007 |
| CVE-2007-1183 | WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors. | HIGH | 7.5 | Feb 28, 2007 |
| CVE-2007-1182 | WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact. | MEDIUM | 6.4 | Feb 28, 2007 |
| CVE-2007-1181 | WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors. | MEDIUM | 5.0 | Feb 28, 2007 |
Showing 1 to 25 of 36 CVEs