gwm CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

gwm vulnerability overview

Aggregates CVE and security vulnerability intelligence across all gwm-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection, vendor risk cross-site scripting, and vendor risk path handling and related problems; some flaws may lead to vendor impact data exposure and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-6300 Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. [email protected] 7.5 2.62% 2009-02-26 2026-04-23
CVE-2008-6249 SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. [email protected] 7.5 0.97% 2009-02-23 2026-04-23
CVE-2008-6108 Cross-site scripting (XSS) vulnerability in result.php in Galatolo WebManager (GWM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the key parameter. [email protected] 4.3 1.09% 2009-02-10 2026-04-23
CVE-2008-2700 SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. [email protected] 7.5 1.00% 2008-06-13 2026-04-23
CVE-2008-2699 Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in (1) the plugin parameter to admin/plugins.php or (2) the com parameter to index.php. [email protected] 7.5 2.29% 2008-06-13 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence