Записи awcm-cms
5 опубликованных записей вендора awcm-cms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-399 Resource Management Errors1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2010-4810Proof of concept | Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHawcm-cms · ar web content manager · CWE-94 | Высокая7,5 | — | 2,3 % | 8 июл. 2011 г. |
28Наблюдать | CVE-2011-0903Proof of concept | Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possiblawcm-cms · ar web content manager · CWE-22 | Средняя6,8 | — | 1,9 % | 7 февр. 2011 г. |
21Наблюдать | CVE-2012-2437Proof of concept | cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cooawcm-cms · ar web content manager · CWE-287 | Средняя5,0 | — | 2,4 % | 26 нояб. 2012 г. |
20Наблюдать | CVE-2012-2438Эксплойта нет | ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows awcm-cms · ar web content manager · CWE-399 | Средняя5,0 | — | 1,6 % | 26 нояб. 2012 г. |
18Наблюдать | CVE-2011-1668Proof of concept | Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote awcm-cms · ar web content manager · CWE-79 | Средняя4,3 | — | 1,7 % | 9 апр. 2011 г. |
- CVE-2010-481031Наблюдать
Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PH
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %awcm-cms · ar web content manager8 июл. 2011 г.
- CVE-2011-090328Наблюдать
Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibl
СредняяCVSS 6,8Proof of conceptEPSS 2 %awcm-cms · ar web content manager7 февр. 2011 г.
- CVE-2012-243721Наблюдать
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary coo
СредняяCVSS 5,0Proof of conceptEPSS 2 %awcm-cms · ar web content manager26 нояб. 2012 г.
- CVE-2012-243820Наблюдать
ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows
СредняяCVSS 5,0Эксплойта нетEPSS 2 %awcm-cms · ar web content manager26 нояб. 2012 г.
- CVE-2011-166818Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote
СредняяCVSS 4,3Proof of conceptEPSS 2 %awcm-cms · ar web content manager9 апр. 2011 г.