Product
webidsupport webid
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-35409
CVE-2024-32166
CVE-2023-47397
CVE-2022-41477
CVE-2020-23359
CVE-2019-11592
CVE-2018-1000882
CVE-2018-1000868
CVE-2018-1000867
CVE-2014-5114
CVE-2014-5101
CVE-2010-4873
CVE-2011-3815
CVE-2008-7119
CVE-2008-7118
CVE-2008-7117
CVE-2008-7116
CVE-2008-1470
all versions
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
all versions
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to
<= 1.2.2
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
<= 1.2.2
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file a
all versions
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to chec
all versions
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php,
<= 1.2.2
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrar
<= 1.2.2
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that
<= 1.2.2
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can re
all versions
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
all versions
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML v
all versions
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script o
all versions
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the install
all versions
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands vi
all versions
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote a
all versions
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a ce
all versions
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary
all versions
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows re