| CVE-2023-47397 |
|
Critical |
Nov 08, 2023 |
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
less...
|
0.3.11, 0.3.10, 0.3.9, 0.3.8, 1.2.2, 1.2.1, 1.2, 0.3.7, 0.3.6, 0.3.5
|
| CVE-2022-41477 |
|
Critical |
Oct 14, 2022 |
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attacker
more...
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
less...
|
0.3.11, 0.3.10, 0.3.9, 0.3.8, 1.2.2, 1.2.1, 1.2, 0.3.7, 0.3.6, 0.3.5
|
| CVE-2018-1000882 |
BDSA-2018-4505 |
High |
Dec 20, 2018 |
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. Th
more...
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
less...
|
0.3.11, 0.3.10, 0.3.9, 0.3.8, 1.2.2, 1.2.1, 1.2, 0.3.7, 0.3.6, 0.3.5
|
| CVE-2018-1000868 |
BDSA-2018-4500 |
Medium |
Dec 20, 2018 |
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javasc
more...
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
less...
|
0.3.11, 0.3.10, 0.3.9, 0.3.8, 1.2.2, 1.2.1, 1.2, 0.3.7, 0.3.6, 0.3.5
|
| CVE-2018-1000867 |
BDSA-2018-4511 |
High |
Dec 20, 2018 |
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read
more...
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
less...
|
0.3.11, 0.3.10, 0.3.9, 0.3.8, 1.2.2, 1.2.1, 1.2, 0.3.7, 0.3.6, 0.3.5
|
| BDSA-2024-3136 |
|
High |
May 29, 2024 |
WeBid 1.1.2 is vulnerable to SQL Injection via `admin/tax.php`.
**Note: CVE details have been utilized in generating this advisory. The details of the
more...
WeBid 1.1.2 is vulnerable to SQL Injection via `admin/tax.php`.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2024-1970 |
|
Medium |
Apr 23, 2024 |
Webid suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is s
more...
Webid suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2019-0290 |
|
High |
Feb 04, 2019 |
Multiple cross-site scripting (XSS) vulnerabilities have been discovered in WeBid. An attacker could exploit this vulnerability by distributing a craft
more...
Multiple cross-site scripting (XSS) vulnerabilities have been discovered in WeBid. An attacker could exploit this vulnerability by distributing a crafted link that executes malicious scripts in the victims browser.
less...
|
|
| BDSA-2016-0628 |
|
Critical |
Nov 09, 2017 |
WeBid is a web auction software. It contains a SQL injection vulnerability that allows a remote non-authenticated attacker to alter an existing SQL que
more...
WeBid is a web auction software. It contains a SQL injection vulnerability that allows a remote non-authenticated attacker to alter an existing SQL query and execute arbitrary SQL commands in the application's database.
This gives an attacker the ability to read, modify and delete arbitrary records within the database and gain the control of the entire site. The vulnerability exists due to the lack of validation of the parameter `id` within the page `/feedback.php`.
An [exploit](https://packetstormsecurity.com/files/135833/WeBid-1.1.2P2-SQL-Injection.html) is available.
less...
|
|
| BDSA-2015-0164 |
|
Critical |
Nov 30, 2017 |
WeBid is a web auction software. It contains an unrestricted file upload vulnerability that allows for dangerous file types to be uploaded including PH
more...
WeBid is a web auction software. It contains an unrestricted file upload vulnerability that allows for dangerous file types to be uploaded including PHP files. A remote unauthenticated attacker could upload a malicious file and result in arbitrary remote code execution (*RCE*). The vulnerable functionality is within the file `/inc/plupload/examples/upload.php`.
less...
|
|