Webspell

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 21
    Known Exploited: 0
    1
    Critical Level Threats
    7
    High Level Threats
    13
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-4861

    SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Last Modified: Apr 11, 2025
    Published: Oct 05, 2011

    CVE-2009-1912

    Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.

    Last Modified: Apr 23, 2026
    Published: Jun 04, 2009

    CVE-2009-1408

    Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.

    Last Modified: Apr 23, 2026
    Published: Apr 24, 2009

    CVE-2008-1481

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Last Modified: Apr 23, 2026
    Published: Mar 24, 2008

    CVE-2008-0575

    Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action.

    Last Modified: Apr 23, 2026
    Published: Feb 05, 2008
    Items Per Page
    Webspell Vulnerabilities & Security CVEs | CVE-DB