Перейти к содержимому
Noroxi

Записи bitweaver

32 опубликованных записей вендора bitweaver.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 3,1 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

32 записей
  • CVE-2012-5192
    36Наблюдать

    Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vi

    СредняяCVSS 5,0Готовый эксплойтEPSS 52 %

    bitweaver · bitweaver27 янв. 2014 г.

  • CVE-2007-6650
    31Наблюдать

    Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    bitweaver · r2 cms4 янв. 2008 г.

  • CVE-2009-1678
    31Наблюдать

    Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    bitweaver · bitweaver18 мая 2009 г.

  • CVE-2005-4380
    31Наблюдать

    Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1)

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    bitweaver · bitweaver19 дек. 2005 г.

  • CVE-2006-6923
    30Наблюдать

    SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL comma

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    bitweaver · bitweaver12 янв. 2007 г.

  • CVE-2007-6375
    30Наблюдать

    Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    bitweaver · bitweaver14 дек. 2007 г.

  • CVE-2006-6925
    28Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    bitweaver · bitweaver12 янв. 2007 г.

  • CVE-2009-1677
    27Наблюдать

    Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1)

    СредняяCVSS 6,5Proof of conceptEPSS 2 %

    bitweaver · bitweaver18 мая 2009 г.

  • CVE-2007-6412
    27Наблюдать

    Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attack

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    bitweaver · bitweaver17 дек. 2007 г.

  • CVE-2012-5193
    25Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    bitweaver · bitweaver13 нояб. 2019 г.

  • CVE-2006-3104
    23Наблюдать

    users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals t

    СредняяCVSS 5,0Proof of conceptEPSS 9 %

    bitweaver · bitweaver20 июн. 2006 г.

  • CVE-2006-3102
    23Наблюдать

    Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execu

    СредняяCVSS 5,1Proof of conceptEPSS 8 %

    bitweaver · bitweaver20 июн. 2006 г.

  • CVE-2007-6651
    21Наблюдать

    Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourc

    СредняяCVSS 5,0Proof of conceptEPSS 4 %

    bitweaver · bitweaver4 янв. 2008 г.

  • CVE-2006-6924
    21Наблюдать

    bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs

    СредняяCVSS 5,0Proof of conceptEPSS 3 %

    bitweaver · bitweaver12 янв. 2007 г.

  • CVE-2006-3105
    21Наблюдать

    CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mu

    СредняяCVSS 5,0Proof of conceptEPSS 3 %

    bitweaver · bitweaver20 июн. 2006 г.

  • CVE-2010-5086
    21Наблюдать

    Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    bitweaver · bitweaver19 мар. 2012 г.

  • CVE-2021-29031
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29025
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29032
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preference

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29030
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/inde

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29029
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_perso

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29028
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29027
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29026
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/perm

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.

  • CVE-2021-29033
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    bitweaver · bitweaver24 мар. 2021 г.