Web App.Net maintains a focused web application product whose vulnerability profile centers on cross-site request forgery weaknesses, a class endemic to stateful web applications where request validation and session handling introduce recurring risks. The vendor's disclosures remain narrowly scoped to this product line and weakness class. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web App.Net over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3242HIGH The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute a | Jun 15, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-1829HIGH Multiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having] other [security] issues too, not as bad as letting users t | Apr 3, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-6688HIGH Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanisms via unknown vectors. NOTE: T | Dec 21, 2006 | 7.5 | 19 | NO | NO |
CVE-2007-3416MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9 | Jun 26, 2007 | 5.0 | 15 | NO | NO |
CVE-2006-7186MEDIUM cgi-lib/subs.pl in web-app.net WebAPP before 0.9.9.3.5 allows attackers to open list files in "profile and other functions," a different vulnerability than CVE-2005-0927. | Apr 3, 2007 | 5.0 | 15 | NO | NO |
CVE-2006-7188MEDIUM The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related | Apr 3, 2007 | 5.0 | 15 | NO | NO |
CVE-2006-7187MEDIUM Cross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to inject | Apr 3, 2007 | 4.3 | 14 | NO | NO |
CVE-2006-7189MEDIUM Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary web script or HTML via unspecif | Apr 3, 2007 | 4.3 | 14 | NO | NO |
CVE-2006-7190MEDIUM Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unsp | Apr 3, 2007 | 4.3 | 14 | NO | NO |
CVE-2006-6687MEDIUM Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbit | Dec 21, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web App.Net.
Media articles that mention a CVE ID that affects a product developed by Web App.Net — matched by CVE ID, not by vendor name.