Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2022-42984
Disclosure Date: November 15, 2022 (last updated December 22, 2024)
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
0
Attacker Value
Unknown
CVE-2022-40405
Disclosure Date: November 15, 2022 (last updated December 22, 2024)
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.
0
Attacker Value
Unknown
CVE-2022-1753
Disclosure Date: May 17, 2022 (last updated October 07, 2023)
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.
0
Attacker Value
Unknown
CVE-2022-26254
Disclosure Date: March 27, 2022 (last updated October 07, 2023)
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
0
Attacker Value
Unknown
CVE-2021-27200
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
0
Attacker Value
Unknown
CVE-2021-26935
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.
0