gonafish records
6 published records for vendor gonafish.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-3884Proof of concept | Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via gonafish · linkscaffe | High7.5 | — | 3.9% | Jul 26, 2006 |
30Monitor | CVE-2008-4202Proof of concept | SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the iddgonafish · linkscaffepro · CWE-89 | High7.5 | — | 1.0% | Sep 24, 2008 |
30Monitor | CVE-2009-4718No exploit | SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via thgonafish · webstatcaffe · CWE-89 | High7.5 | — | 1.0% | Mar 15, 2010 |
20Monitor | CVE-2006-3932No exploit | SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 allows remote attackers to execute arbitrary SQL commands via the cat pagonafish · linkscaffe | Medium5.1 | — | 1.1% | Jul 31, 2006 |
18Monitor | CVE-2006-3883Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTMLgonafish · linkscaffe | Medium4.3 | — | 4.8% | Jul 26, 2006 |
17Monitor | CVE-2009-4717Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML vgonafish · webstatcaffe · CWE-79 | Medium4.3 | — | 1.3% | Mar 15, 2010 |
- CVE-2006-388431Monitor
Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 4%gonafish · linkscaffeJul 26, 2006
- CVE-2008-420230Monitor
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd
HighCVSS 7.5Proof of conceptEPSS 1%gonafish · linkscaffeproSep 24, 2008
- CVE-2009-471830Monitor
SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5No exploitEPSS 1%gonafish · webstatcaffeMar 15, 2010
- CVE-2006-393220Monitor
SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 allows remote attackers to execute arbitrary SQL commands via the cat pa
MediumCVSS 5.1No exploitEPSS 1%gonafish · linkscaffeJul 31, 2006
- CVE-2006-388318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 5%gonafish · linkscaffeJul 26, 2006
- CVE-2009-471717Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML v
MediumCVSS 4.3Proof of conceptEPSS 1%gonafish · webstatcaffeMar 15, 2010