Skip to main content

Vendor/product archive

gwm / galatolo_webmanager CVEs

Beta · best-effort

5 CVEs tagged to gwm / galatolo_webmanager0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2008-6300

Published Feb 26, 2009

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6249

Published Feb 23, 2009

SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6108

Published Feb 10, 2009

Cross-site scripting (XSS) vulnerability in result.php in Galatolo WebManager (GWM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the key parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2699

Published Jun 13, 2008

Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2700

Published Jun 13, 2008

SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1