Webidsupport / Webid
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-35409 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. | CRITICAL | 9.8 | May 22, 2024 |
| CVE-2024-32166 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is su… | HIGH | 8.8 | Apr 19, 2024 |
| CVE-2023-47397 | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | CRITICAL | 9.8 | Nov 8, 2023 |
| CVE-2022-41477 | A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inj… | CRITICAL | 9.1 | Oct 14, 2022 |
| CVE-2020-23359 | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two pa… | CRITICAL | 9.8 | Jan 27, 2021 |
| CVE-2019-11592 | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or… | MEDIUM | 6.1 | Apr 29, 2019 |
| CVE-2018-1000882 | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attac… | HIGH | 7.5 | Dec 20, 2018 |
| CVE-2018-1000868 | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript exe… | MEDIUM | 6.1 | Dec 20, 2018 |
| CVE-2018-1000867 | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Bli… | HIGH | 8.8 | Dec 20, 2018 |
| CVE-2014-5114 | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. | HIGH | 7.5 | Jul 29, 2014 |
| CVE-2014-5101 | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_… | MEDIUM | 4.3 | Jul 25, 2014 |
| CVE-2010-4873 | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | MEDIUM | 4.3 | Oct 7, 2011 |
| CVE-2011-3815 | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error messag… | MEDIUM | 5.0 | Sep 24, 2011 |
| CVE-2008-7119 | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | HIGH | 7.5 | Aug 28, 2009 |
| CVE-2008-7118 | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query… | MEDIUM | 5.0 | Aug 28, 2009 |
| CVE-2008-7117 | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file p… | MEDIUM | 5.0 | Aug 28, 2009 |
| CVE-2008-7116 | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the usernam… | HIGH | 7.5 | Aug 28, 2009 |
Showing 1 to 17 of 17 CVEs