CVE-2024-35409
- EPSS 0.18%
- Veröffentlicht 22.05.2024 14:15:08
- Zuletzt bearbeitet 28.05.2025 19:59:10
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
CVE-2024-32166
- EPSS 0.16%
- Veröffentlicht 19.04.2024 14:15:11
- Zuletzt bearbeitet 03.06.2025 14:02:49
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
CVE-2023-47397
- EPSS 0.28%
- Veröffentlicht 08.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:30:14
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
CVE-2022-41477
- EPSS 0.24%
- Veröffentlicht 14.10.2022 19:15:19
- Zuletzt bearbeitet 14.05.2025 16:15:23
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
CVE-2020-23359
- EPSS 0.36%
- Veröffentlicht 27.01.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:46
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
CVE-2019-11592
- EPSS 0.24%
- Veröffentlicht 29.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:24
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
CVE-2018-1000882
- EPSS 0.5%
- Veröffentlicht 20.12.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:34
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This vulnerability appears to have been fi...
CVE-2018-1000867
- EPSS 0.37%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability...
CVE-2018-1000868
- EPSS 0.48%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appe...
CVE-2014-5114
- EPSS 0.43%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.