falcon records
4 published records for vendor falcon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2007-6489Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or falcon · series one cms | High7.5 | — | 6.8% | Dec 20, 2007 |
28Monitor | CVE-2007-6488Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via afalcon · series one cms · CWE-20 | Medium6.8 | — | 2.7% | Dec 20, 2007 |
21Monitor | CVE-1999-0882No exploit | Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.falcon · falcon web server | Medium5.0 | — | 1.9% | Oct 28, 1999 |
17Monitor | CVE-2007-6490Proof of concept | Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain chfalcon · series one cms · CWE-352 | Medium4.3 | — | 0.9% | Dec 20, 2007 |
- CVE-2007-648932Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or
HighCVSS 7.5Proof of conceptEPSS 7%falcon · series one cmsDec 20, 2007
- CVE-2007-648828Monitor
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a
MediumCVSS 6.8Proof of conceptEPSS 3%falcon · series one cmsDec 20, 2007
- CVE-1999-088221Monitor
Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.
MediumCVSS 5.0No exploitEPSS 2%falcon · falcon web serverOct 28, 1999
- CVE-2007-649017Monitor
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain ch
MediumCVSS 4.3Proof of conceptEPSS 1%falcon · series one cmsDec 20, 2007