Skip to main content

Vendor/product archive

derbynet / derbynet CVEs

Beta · best-effort

11 CVEs tagged to derbynet / derbynet3 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-30929

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30928

Published Apr 18, 2024

SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30927

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30926

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30925

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30924

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30923

Published Apr 18, 2024

SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30922

Published Apr 18, 2024

SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30921

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30920

Published Apr 18, 2024

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31818

Published Apr 12, 2024

Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1