Записи bitweaver
32 опубликованных записей вендора bitweaver.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,1 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
32 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2012-5192Готовый эксплойт | Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vibitweaver · bitweaver · CWE-22 | Средняя5,0 | — | 52,5 % | 27 янв. 2014 г. |
31Наблюдать | CVE-2007-6650Proof of concept | Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using bitweaver · r2 cms · CWE-264 | Высокая7,5 | — | 2,9 % | 4 янв. 2008 г. |
31Наблюдать | CVE-2009-1678Proof of concept | Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackersbitweaver · bitweaver · CWE-22 | Высокая7,5 | — | 2,4 % | 18 мая 2009 г. |
31Наблюдать | CVE-2005-4380Proof of concept | Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) bitweaver · bitweaver · CWE-89 | Высокая7,5 | — | 2,2 % | 19 дек. 2005 г. |
30Наблюдать | CVE-2006-6923Proof of concept | SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commabitweaver · bitweaver | Высокая7,5 | — | 1,1 % | 12 янв. 2007 г. |
30Наблюдать | CVE-2007-6375Proof of concept | Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbitweaver · bitweaver · CWE-89 | Высокая7,5 | — | 1,0 % | 14 дек. 2007 г. |
28Наблюдать | CVE-2006-6925Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or bitweaver · bitweaver | Средняя6,8 | — | 2,1 % | 12 янв. 2007 г. |
27Наблюдать | CVE-2009-1677Proof of concept | Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) bitweaver · bitweaver · CWE-94 | Средняя6,5 | — | 2,1 % | 18 мая 2009 г. |
27Наблюдать | CVE-2007-6412Эксплойта нет | Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackbitweaver · bitweaver · CWE-94 | Средняя6,8 | — | 1,5 % | 17 дек. 2007 г. |
25Наблюдать | CVE-2012-5193Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or bitweaver · bitweaver · CWE-79 | Средняя6,1 | — | 1,8 % | 13 нояб. 2019 г. |
23Наблюдать | CVE-2006-3104Proof of concept | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals tbitweaver · bitweaver | Средняя5,0 | — | 8,9 % | 20 июн. 2006 г. |
23Наблюдать | CVE-2006-3102Proof of concept | Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execubitweaver · bitweaver | Средняя5,1 | — | 8,5 % | 20 июн. 2006 г. |
21Наблюдать | CVE-2007-6651Proof of concept | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourcbitweaver · bitweaver · CWE-22 | Средняя5,0 | — | 3,7 % | 4 янв. 2008 г. |
21Наблюдать | CVE-2006-6924Proof of concept | bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogsbitweaver · bitweaver | Средняя5,0 | — | 3,4 % | 12 янв. 2007 г. |
21Наблюдать | CVE-2006-3105Proof of concept | CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mubitweaver · bitweaver | Средняя5,0 | — | 2,7 % | 20 июн. 2006 г. |
21Наблюдать | CVE-2010-5086Эксплойта нет | Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..bitweaver · bitweaver · CWE-22 | Средняя5,0 | — | 1,8 % | 19 мар. 2012 г. |
19Наблюдать | CVE-2021-29031Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/userbitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,9 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29025Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.bitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29032Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preferencebitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29030Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/indebitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29029Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_persobitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29028Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/userbitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29027Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php bitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29026Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/permbitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
19Наблюдать | CVE-2021-29033Эксплойта нет | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/editbitweaver · bitweaver · CWE-79 | Средняя4,8 | — | 0,8 % | 24 мар. 2021 г. |
- CVE-2012-519236Наблюдать
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vi
СредняяCVSS 5,0Готовый эксплойтEPSS 52 %bitweaver · bitweaver27 янв. 2014 г.
- CVE-2007-665031Наблюдать
Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %bitweaver · r2 cms4 янв. 2008 г.
- CVE-2009-167831Наблюдать
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %bitweaver · bitweaver18 мая 2009 г.
- CVE-2005-438031Наблюдать
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %bitweaver · bitweaver19 дек. 2005 г.
- CVE-2006-692330Наблюдать
SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %bitweaver · bitweaver12 янв. 2007 г.
- CVE-2007-637530Наблюдать
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %bitweaver · bitweaver14 дек. 2007 г.
- CVE-2006-692528Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 6,8Proof of conceptEPSS 2 %bitweaver · bitweaver12 янв. 2007 г.
- CVE-2009-167727Наблюдать
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1)
СредняяCVSS 6,5Proof of conceptEPSS 2 %bitweaver · bitweaver18 мая 2009 г.
- CVE-2007-641227Наблюдать
Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attack
СредняяCVSS 6,8Эксплойта нетEPSS 2 %bitweaver · bitweaver17 дек. 2007 г.
- CVE-2012-519325Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 6,1Proof of conceptEPSS 2 %bitweaver · bitweaver13 нояб. 2019 г.
- CVE-2006-310423Наблюдать
users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals t
СредняяCVSS 5,0Proof of conceptEPSS 9 %bitweaver · bitweaver20 июн. 2006 г.
- CVE-2006-310223Наблюдать
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execu
СредняяCVSS 5,1Proof of conceptEPSS 8 %bitweaver · bitweaver20 июн. 2006 г.
- CVE-2007-665121Наблюдать
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourc
СредняяCVSS 5,0Proof of conceptEPSS 4 %bitweaver · bitweaver4 янв. 2008 г.
- CVE-2006-692421Наблюдать
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs
СредняяCVSS 5,0Proof of conceptEPSS 3 %bitweaver · bitweaver12 янв. 2007 г.
- CVE-2006-310521Наблюдать
CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mu
СредняяCVSS 5,0Proof of conceptEPSS 3 %bitweaver · bitweaver20 июн. 2006 г.
- CVE-2010-508621Наблюдать
Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bitweaver · bitweaver19 мар. 2012 г.
- CVE-2021-2903119Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2902519Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2903219Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preference
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2903019Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/inde
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2902919Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_perso
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2902819Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2902719Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2902619Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/perm
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.
- CVE-2021-2903319Наблюдать
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit
СредняяCVSS 4,8Эксплойта нетEPSS 1 %bitweaver · bitweaver24 мар. 2021 г.