Записи asp-nuke
13 опубликованных записей вендора asp-nuke.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2006-7152Proof of concept | default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.asp-nuke · asp-nuke | Высокая8,5 | — | 2,5 % | 7 мар. 2007 г. |
30Наблюдать | CVE-2002-0522Эксплойта нет | ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.asp-nuke · asp-nuke | Высокая7,5 | — | 1,6 % | 12 авг. 2002 г. |
30Наблюдать | CVE-2002-0520Эксплойта нет | Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users basp-nuke · asp-nuke | Высокая7,5 | — | 1,6 % | 12 авг. 2002 г. |
30Наблюдать | CVE-2005-2066Proof of concept | SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID asp-nuke · asp-nuke | Высокая7,5 | — | 1,1 % | 29 июн. 2005 г. |
30Наблюдать | CVE-2005-2067Proof of concept | SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the asp-nuke · asp-nuke | Высокая7,5 | — | 1,1 % | 29 июн. 2005 г. |
30Наблюдать | CVE-2006-6070Proof of concept | SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrarasp-nuke · asp-nuke | Высокая7,5 | — | 1,1 % | 21 нояб. 2006 г. |
21Наблюдать | CVE-2004-1788Proof of concept | ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackersasp-nuke · asp-nuke | Средняя5,0 | — | 2,7 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2002-0521Эксплойта нет | Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuasp-nuke · asp-nuke | Средняя5,1 | — | 2,3 % | 12 авг. 2002 г. |
21Наблюдать | CVE-2005-2064Proof of concept | Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) emaasp-nuke · asp-nuke | Средняя5,0 | — | 2,0 % | 29 июн. 2005 г. |
21Наблюдать | CVE-2002-0524Эксплойта нет | ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrectasp-nuke · asp-nuke | Средняя5,0 | — | 1,9 % | 12 авг. 2002 г. |
21Наблюдать | CVE-2002-0523Эксплойта нет | ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.asp-nuke · asp-nuke | Средняя5,0 | — | 1,9 % | 12 авг. 2002 г. |
21Наблюдать | CVE-2005-2065Proof of concept | HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caasp-nuke · asp-nuke | Средняя5,0 | — | 1,9 % | 29 июн. 2005 г. |
17Наблюдать | CVE-2007-2892Proof of concept | Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via thasp-nuke · asp-nuke | Средняя4,3 | — | 1,5 % | 29 мая 2007 г. |
- CVE-2006-715235Наблюдать
default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.
ВысокаяCVSS 8,5Proof of conceptEPSS 2 %asp-nuke · asp-nuke7 мар. 2007 г.
- CVE-2002-052230Наблюдать
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %asp-nuke · asp-nuke12 авг. 2002 г.
- CVE-2002-052030Наблюдать
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users b
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %asp-nuke · asp-nuke12 авг. 2002 г.
- CVE-2005-206630Наблюдать
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-nuke · asp-nuke29 июн. 2005 г.
- CVE-2005-206730Наблюдать
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-nuke · asp-nuke29 июн. 2005 г.
- CVE-2006-607030Наблюдать
SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrar
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %asp-nuke · asp-nuke21 нояб. 2006 г.
- CVE-2004-178821Наблюдать
ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers
СредняяCVSS 5,0Proof of conceptEPSS 3 %asp-nuke · asp-nuke31 дек. 2004 г.
- CVE-2002-052121Наблюдать
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nu
СредняяCVSS 5,1Эксплойта нетEPSS 2 %asp-nuke · asp-nuke12 авг. 2002 г.
- CVE-2005-206421Наблюдать
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) ema
СредняяCVSS 5,0Proof of conceptEPSS 2 %asp-nuke · asp-nuke29 июн. 2005 г.
- CVE-2002-052421Наблюдать
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect
СредняяCVSS 5,0Эксплойта нетEPSS 2 %asp-nuke · asp-nuke12 авг. 2002 г.
- CVE-2002-052321Наблюдать
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %asp-nuke · asp-nuke12 авг. 2002 г.
- CVE-2005-206521Наблюдать
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web ca
СредняяCVSS 5,0Proof of conceptEPSS 2 %asp-nuke · asp-nuke29 июн. 2005 г.
- CVE-2007-289217Наблюдать
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via th
СредняяCVSS 4,3Proof of conceptEPSS 1 %asp-nuke · asp-nuke29 мая 2007 г.