Vendorsw2bonline_bankingall versions
Vulnerabilities

w2b Online Banking

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2007-3175
Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b.
Published 2007-06-11 · Modified
7.5EPSS 0.167
CVE-2008-1893
PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter.
Published 2008-04-18 · Modified
7.51 PoCEPSS 0.023
CVE-2007-3174
Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vector than CVE-2006-1980.
Published 2007-06-11 · Modified
4.3EPSS 0.010
CVE-2006-1980
Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.
Published 2006-04-21 · Modified
2.61 PoCEPSS 0.020