exv2 kayıtları
exv2 üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2006-7079Kavram kanıtı | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program vexv2 · content management system · CWE-22 | Kritik9,8 | — | %12,9 | 2 Mar 2007 |
36İzleyin | CVE-2007-1966İstismar yok | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookiexv2 · content management system · CWE-287 | Kritik9,1 | — | %1,2 | 11 Nis 2007 |
30İzleyin | CVE-2008-1349Kavram kanıtı | SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers toexv2 · bamagalerie · CWE-89 | Yüksek7,5 | — | %1,2 | 17 Mar 2008 |
30İzleyin | CVE-2006-5030Kavram kanıtı | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitraryexv2 · content management system | Yüksek7,5 | — | %1,1 | 27 Eyl 2006 |
27İzleyin | CVE-2008-1404Kavram kanıtı | SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrexv2 · exv2 · CWE-89 | Orta6,8 | — | %0,9 | 20 Mar 2008 |
27İzleyin | CVE-2008-1407Kavram kanıtı | SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via texv2 · exv2 · CWE-89 | Orta6,8 | — | %0,9 | 20 Mar 2008 |
27İzleyin | CVE-2008-1406Kavram kanıtı | SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commaexv2 · exv2 · CWE-89 | Orta6,8 | — | %0,9 | 20 Mar 2008 |
18İzleyin | CVE-2006-7080Kavram kanıtı | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary filesexv2 · content management system | Orta4,3 | — | %4,7 | 2 Mar 2007 |
17İzleyin | CVE-2010-4155İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (exv2 · exv2 · CWE-79 | Orta4,3 | — | %1,1 | 3 Kas 2010 |
17İzleyin | CVE-2007-4365İstismar yok | Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a exv2 · content management system | Orta4,3 | — | %1,1 | 15 Ağu 2007 |
17İzleyin | CVE-2007-1965İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script orexv2 · content management system | Orta4,3 | — | %1,0 | 11 Nis 2007 |
- CVE-2006-707943Planlayın
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program v
KritikCVSS 9,8Kavram kanıtıEPSS %13exv2 · content management system2 Mar 2007
- CVE-2007-196636İzleyin
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cooki
KritikCVSS 9,1İstismar yokEPSS %1exv2 · content management system11 Nis 2007
- CVE-2008-134930İzleyin
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %1exv2 · bamagalerie17 Mar 2008
- CVE-2006-503030İzleyin
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %1exv2 · content management system27 Eyl 2006
- CVE-2008-140427İzleyin
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitr
OrtaCVSS 6,8Kavram kanıtıEPSS %1exv2 · exv220 Mar 2008
- CVE-2008-140727İzleyin
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via t
OrtaCVSS 6,8Kavram kanıtıEPSS %1exv2 · exv220 Mar 2008
- CVE-2008-140627İzleyin
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL comma
OrtaCVSS 6,8Kavram kanıtıEPSS %1exv2 · exv220 Mar 2008
- CVE-2006-708018İzleyin
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files
OrtaCVSS 4,3Kavram kanıtıEPSS %5exv2 · content management system2 Mar 2007
- CVE-2010-415517İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (
OrtaCVSS 4,3İstismar yokEPSS %1exv2 · exv23 Kas 2010
- CVE-2007-436517İzleyin
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a
OrtaCVSS 4,3İstismar yokEPSS %1exv2 · content management system15 Ağu 2007
- CVE-2007-196517İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %1exv2 · content management system11 Nis 2007