CVE Tools

Webspell

14 CVEs tracked since 2006. Since Sep 2006, none of them reached CISA KEV.

Webspell CVEs per month

Sep 2006 to Oct 2011. Point at a month, or focus the strip and use the arrow keys.
Webspell CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-0920
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-0120
2007-0250
2007-03null or fewer
2007-0420
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-0220
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-1010

Products

The products that kept showing up in Webspell's monthly top three, with their CVEs summed over those months.

  1. Webspell146 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Webspell.

  1. CVE-2010-4861SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.7.5
  2. CVE-2009-1912Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language ...6.8
  3. CVE-2009-1408Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascr...4.3
  4. CVE-2008-1481Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board parameter. NOTE: the provenance of this informa...4.3
  5. CVE-2008-0575Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators...4.3
  6. CVE-2008-0574Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.4.3
  7. CVE-2007-6309Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upl...4.3
  8. CVE-2007-4028Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of...7.5
  9. CVE-2007-2368picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.5.0
  10. CVE-2007-2369Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.5.0
  11. CVE-2007-1163SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019...7.5
  12. CVE-2007-1160webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.10.0
  13. CVE-2007-1154SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.6.8
  14. CVE-2007-1155Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue may be an adminis...4.6
  15. CVE-2007-1019SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a d...6.8

The record

Peak rank
#18 in Feb 2007
Busiest month shown
Feb 2007, 5 CVEs
Months with a KEV entry
0 since Sep 2006
Monthly snapshots
6 since 2006
Webspell's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store