Web-app.Org

Webapp

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impact and remote attack vectors.

  • EPSS 0.13%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9.6; and (b) web-app.net WebAPP 0.9.9.3.3, 0.9.9.3.4, and 2007; allow r...

  • EPSS 0.28%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string, which is not sanitized when an HREF attribute is ...

  • EPSS 0.45%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authenticated users to impersonate other users.

  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.dat, (6) states.dat, and (7) ages.dat files before s...

  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has...

  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0.9.9.7 do not verify presence of users in memberlist.d...

  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encod...

  • EPSS 0.37%
  • Veröffentlicht 26.06.2007 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) gue...

  • EPSS 0.92%
  • Veröffentlicht 15.06.2007 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a...