easyscripts records
6 published records for vendor easyscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2001-1437No exploit | easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message easyscripts · easynews | High7.5 | — | 2.1% | Dec 1, 2001 |
30Monitor | CVE-2008-1957Proof of concept | SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parametereasyscripts · tr script news · CWE-89 | High7.5 | — | 1.2% | Apr 25, 2008 |
27Monitor | CVE-2008-1958Proof of concept | Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to exeasyscripts · tr script news · CWE-94 | Medium6.5 | — | 3.3% | Apr 25, 2008 |
21Monitor | CVE-2001-1525Proof of concept | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.daeasyscripts · easynews | Medium5.0 | — | 2.5% | Dec 31, 2001 |
17Monitor | CVE-2001-1526No exploit | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject aeasyscripts · easynews | Medium4.3 | — | 1.0% | Dec 31, 2001 |
8Monitor | CVE-2001-1527No exploit | easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and easyscripts · easynews | Low2.1 | — | 0.3% | Dec 31, 2001 |
- CVE-2001-143731Monitor
easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message
HighCVSS 7.5No exploitEPSS 2%easyscripts · easynewsDec 1, 2001
- CVE-2008-195730Monitor
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter
HighCVSS 7.5Proof of conceptEPSS 1%easyscripts · tr script newsApr 25, 2008
- CVE-2008-195827Monitor
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to ex
MediumCVSS 6.5Proof of conceptEPSS 3%easyscripts · tr script newsApr 25, 2008
- CVE-2001-152521Monitor
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.da
MediumCVSS 5.0Proof of conceptEPSS 3%easyscripts · easynewsDec 31, 2001
- CVE-2001-152617Monitor
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 1%easyscripts · easynewsDec 31, 2001
- CVE-2001-15278Monitor
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and
LowCVSS 2.1No exploitEPSS 0%easyscripts · easynewsDec 31, 2001