aj-fork records
3 published records for vendor aj-fork.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2004-1573No exploit | The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbaj-fork · aj-fork | High7.2 | — | 0.5% | Dec 31, 2004 |
21Monitor | CVE-2004-1572No exploit | AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attaj-fork · aj-fork | Medium5.0 | — | 2.2% | Dec 31, 2004 |
20Monitor | CVE-2004-1571No exploit | AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) oaj-fork · aj-fork | Medium5.0 | — | 1.6% | Dec 31, 2004 |
- CVE-2004-157328Monitor
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arb
HighCVSS 7.2No exploitEPSS 0%aj-fork · aj-forkDec 31, 2004
- CVE-2004-157221Monitor
AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote att
MediumCVSS 5.0No exploitEPSS 2%aj-fork · aj-forkDec 31, 2004
- CVE-2004-157120Monitor
AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) o
MediumCVSS 5.0No exploitEPSS 2%aj-fork · aj-forkDec 31, 2004