Skip to main content

Vendor archive

w2b CVEs

Beta · best-effort

14 CVEs tagged to vendor w2b0 Critical, 9 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2008-6921

Published Aug 10, 2009

Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then acce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6920

Published Aug 10, 2009

Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension during a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6849

Published Jul 7, 2009

Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6848

Published Jul 7, 2009

Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML via the category parameter in a select ac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2179

Published Jun 23, 2009

SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2178

Published Jun 23, 2009

Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3179

Published Jul 15, 2008

Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and execute arbitrary local files v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1893

Published Apr 18, 2008

PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1843

Published Apr 16, 2008

SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via the age_to parameter in a browsebyCat a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1844

Published Apr 16, 2008

SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3174

Published Jun 11, 2007

Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3175

Published Jun 11, 2007

Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1980

Published Apr 21, 2006

Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) i…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4088

Published Dec 8, 2005

SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1