citrusdb kayıtları
citrusdb üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2005-0408Kavram kanıtı | CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers tocitrusdb · citrusdb · CWE-916 | Kritik9,8 | — | %4,7 | 14 Şub 2005 |
31İzleyin | CVE-2005-0411Kavram kanıtı | Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary Pcitrusdb · citrusdb | Yüksek7,5 | — | %2,4 | 14 Şub 2005 |
27İzleyin | CVE-2005-0409Kavram kanıtı | CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to uplcitrusdb · citrusdb | Orta6,4 | — | %5,7 | 14 Şub 2005 |
22İzleyin | CVE-2005-0229Kavram kanıtı | CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit cardcitrusdb · citrusdb customer database | Orta5,0 | — | %7,7 | 27 Nis 2005 |
21İzleyin | CVE-2005-0410Kavram kanıtı | SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV ficitrusdb · citrusdb | Orta5,0 | — | %1,8 | 14 Şub 2005 |
- CVE-2005-040840Planlayın
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to
KritikCVSS 9,8Kavram kanıtıEPSS %5citrusdb · citrusdb14 Şub 2005
- CVE-2005-041131İzleyin
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary P
YüksekCVSS 7,5Kavram kanıtıEPSS %2citrusdb · citrusdb14 Şub 2005
- CVE-2005-040927İzleyin
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upl
OrtaCVSS 6,4Kavram kanıtıEPSS %6citrusdb · citrusdb14 Şub 2005
- CVE-2005-022922İzleyin
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card
OrtaCVSS 5,0Kavram kanıtıEPSS %8citrusdb · citrusdb customer database27 Nis 2005
- CVE-2005-041021İzleyin
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV fi
OrtaCVSS 5,0Kavram kanıtıEPSS %2citrusdb · citrusdb14 Şub 2005