exponent kayıtları
exponent üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2006-1604İstismar yok | Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not exponent · exponent cms | Kritik10,0 | — | %1,7 | 4 Nis 2006 |
40Planlayın | CVE-2005-3764İstismar yok | The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded filesexponent · exponent | Kritik10,0 | — | %1,4 | 22 Kas 2005 |
31İzleyin | CVE-2006-1605İstismar yok | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknoexponent · exponent cms | Yüksek7,5 | — | %2,8 | 4 Nis 2006 |
31İzleyin | CVE-2005-3765İstismar yok | Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers toexponent · exponent | Yüksek7,5 | — | %2,7 | 22 Kas 2005 |
30İzleyin | CVE-2005-3762İstismar yok | SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers toexponent · exponent | Yüksek7,5 | — | %1,5 | 22 Kas 2005 |
30İzleyin | CVE-2006-1607İstismar yok | Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.exponent · exponent cms | Yüksek7,5 | — | %1,5 | 4 Nis 2006 |
27İzleyin | CVE-2006-4963Kavram kanıtı | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via exponent · exponent cms | Orta6,4 | — | %7,0 | 23 Eyl 2006 |
21İzleyin | CVE-2007-2252Kavram kanıtı | Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive infexponent · exponent cms | Orta5,0 | — | %2,8 | 25 Nis 2007 |
21İzleyin | CVE-2005-0310İstismar yok | Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.infoexponent · exponent | Orta5,0 | — | %1,7 | 2 May 2005 |
20İzleyin | CVE-2005-3763İstismar yok | Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackersexponent · exponent | Orta5,0 | — | %1,4 | 22 Kas 2005 |
20İzleyin | CVE-2005-3767İstismar yok | Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and eexponent · exponent | Orta5,0 | — | %1,4 | 22 Kas 2005 |
20İzleyin | CVE-2007-2253İstismar yok | Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrolexponent · exponent cms · CWE-200 | Orta5,0 | — | %1,3 | 25 Nis 2007 |
20İzleyin | CVE-2006-1606İstismar yok | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.exponent · exponent cms | Orta5,0 | — | %1,2 | 4 Nis 2006 |
20İzleyin | CVE-2005-3766İstismar yok | Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though exponent · exponent | Orta5,0 | — | %1,2 | 22 Kas 2005 |
17İzleyin | CVE-2005-0309İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrexponent · exponent | Orta4,3 | — | %1,2 | 25 Oca 2005 |
17İzleyin | CVE-2005-3761İstismar yok | Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script orexponent · exponent | Orta4,3 | — | %1,2 | 22 Kas 2005 |
- CVE-2006-160441Planlayın
Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not
KritikCVSS 10,0İstismar yokEPSS %2exponent · exponent cms4 Nis 2006
- CVE-2005-376440Planlayın
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files
KritikCVSS 10,0İstismar yokEPSS %1exponent · exponent22 Kas 2005
- CVE-2006-160531İzleyin
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unkno
YüksekCVSS 7,5İstismar yokEPSS %3exponent · exponent cms4 Nis 2006
- CVE-2005-376531İzleyin
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %3exponent · exponent22 Kas 2005
- CVE-2005-376230İzleyin
SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %1exponent · exponent22 Kas 2005
- CVE-2006-160730İzleyin
Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.
YüksekCVSS 7,5İstismar yokEPSS %1exponent · exponent cms4 Nis 2006
- CVE-2006-496327İzleyin
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via
OrtaCVSS 6,4Kavram kanıtıEPSS %7exponent · exponent cms23 Eyl 2006
- CVE-2007-225221İzleyin
Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive inf
OrtaCVSS 5,0Kavram kanıtıEPSS %3exponent · exponent cms25 Nis 2007
- CVE-2005-031021İzleyin
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info
OrtaCVSS 5,0İstismar yokEPSS %2exponent · exponent2 May 2005
- CVE-2005-376320İzleyin
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers
OrtaCVSS 5,0İstismar yokEPSS %1exponent · exponent22 Kas 2005
- CVE-2005-376720İzleyin
Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and e
OrtaCVSS 5,0İstismar yokEPSS %1exponent · exponent22 Kas 2005
- CVE-2007-225320İzleyin
Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol
OrtaCVSS 5,0İstismar yokEPSS %1exponent · exponent cms25 Nis 2007
- CVE-2006-160620İzleyin
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.
OrtaCVSS 5,0İstismar yokEPSS %1exponent · exponent cms4 Nis 2006
- CVE-2005-376620İzleyin
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though
OrtaCVSS 5,0İstismar yokEPSS %1exponent · exponent22 Kas 2005
- CVE-2005-030917İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitr
OrtaCVSS 4,3İstismar yokEPSS %1exponent · exponent25 Oca 2005
- CVE-2005-376117İzleyin
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %1exponent · exponent22 Kas 2005