Skip to content
Noroxi

envolution records

4 published records for vendor envolution.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    4 records
    • CVE-2006-6445
      32Monitor

      Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary loca

      HighCVSS 7.5Proof of conceptEPSS 7%

      envolution · envolutionDec 10, 2006

    • CVE-2005-4263
      30Monitor

      SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow

      HighCVSS 7.5Proof of conceptEPSS 1%

      envolution · envolutionDec 15, 2005

    • CVE-2007-4253
      30Monitor

      SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary S

      HighCVSS 7.5Proof of conceptEPSS 1%

      envolution · envolutionAug 8, 2007

    • CVE-2005-4262
      17Monitor

      Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via

      MediumCVSS 4.3Proof of conceptEPSS 1%

      envolution · envolutionDec 15, 2005