CVE Tools

Mywebland

28 CVEs tracked since 2005. Since Apr 2005, none of them reached CISA KEV.

Mywebland CVEs per month

Apr 2005 to Nov 2008. Point at a month, or focus the strip and use the arrow keys.
Mywebland CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0410
2005-0540
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-0910
2005-1010
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-0430
2006-05null or fewer
2006-06null or fewer
2006-0720
2006-0850
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-0630
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-0730
2008-08null or fewer
2008-09null or fewer
2008-1040
2008-1110

Products

The products that kept showing up in Mywebland's monthly top three, with their CVEs summed over those months.

  1. Mybloggie168 months
  2. Myevent74 months
  3. Minibloggie22 months
  4. Mystats21 month
  5. Bloggie Lite11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mywebland.

  1. CVE-2008-6650del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628.5.0
  2. CVE-2008-5004SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbitrary SQL commands via a crafted cookie.7.5
  3. CVE-2008-4650SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.7.5
  4. CVE-2008-4643SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.7.5
  5. CVE-2008-4644hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.7.5
  6. CVE-2008-4628SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter.7.5
  7. CVE-2008-3080Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute ...5.1
  8. CVE-2007-3650myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; an...5.3
  9. CVE-2007-1899Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and all...5.1
  10. CVE-2007-3353PHP remote file inclusion vulnerability in includes/template.php in MyEvent 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter. NOTE: a reliable thir...7.5
  11. CVE-2007-3194Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php...9.8
  12. CVE-2007-3003Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser ac...7.5
  13. CVE-2007-0353Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.6.8
  14. CVE-2006-4163PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NO...7.5
  15. CVE-2006-4083PHP remote file inclusion vulnerability in viewevent.php in myWebland myEvent 1.x allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter, a different vector t...7.5

The record

Peak rank
#17 in Aug 2006
Busiest month shown
Aug 2006, 5 CVEs
Months with a KEV entry
0 since Apr 2005
Monthly snapshots
11 since 2005
Mywebland's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store