Skip to content
Noroxi

aj-fork records

3 published records for vendor aj-fork.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      3 records
      • CVE-2004-1573
        28Monitor

        The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arb

        HighCVSS 7.2No exploitEPSS 0%

        aj-fork · aj-forkDec 31, 2004

      • CVE-2004-1572
        21Monitor

        AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote att

        MediumCVSS 5.0No exploitEPSS 2%

        aj-fork · aj-forkDec 31, 2004

      • CVE-2004-1571
        20Monitor

        AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) o

        MediumCVSS 5.0No exploitEPSS 2%

        aj-fork · aj-forkDec 31, 2004