İçeriğe atla
Noroxi

jetbox kayıtları

jetbox üreticisine ait 21 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

21 kayıt
  • CVE-2006-2270
    34İzleyin

    PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL

    YüksekCVSS 7,5Kavram kanıtıEPSS %14

    jetbox · jetbox cms9 May 2006

  • CVE-2006-4422
    32İzleyin

    PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arb

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    jetbox · jetbox cms28 Ağu 2006

  • CVE-2006-3583
    31İzleyin

    Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator

    YüksekCVSS 7,5İstismar yokEPSS %2

    jetbox · jetbox cms8 Ağu 2006

  • CVE-2006-3584
    30İzleyin

    Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables vi

    YüksekCVSS 7,5İstismar yokEPSS %2

    jetbox · jetbox cms8 Ağu 2006

  • CVE-2006-4738
    30İzleyin

    PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the

    YüksekCVSS 7,5İstismar yokEPSS %1

    jetbox · jetbox cms13 Eyl 2006

  • CVE-2006-3586
    30İzleyin

    SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to execute arbitrary SQL commands via the (1) frontsession COOKIE

    YüksekCVSS 7,5İstismar yokEPSS %1

    jetbox · jetbox cms8 Ağu 2006

  • CVE-2006-4737
    30İzleyin

    SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter

    YüksekCVSS 7,5İstismar yokEPSS %1

    jetbox · jetbox cms13 Eyl 2006

  • CVE-2007-2685
    30İzleyin

    Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) v

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    jetbox · jetbox cms21 May 2007

  • CVE-2007-2732
    28İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1)

    OrtaCVSS 6,8Kavram kanıtıEPSS %4

    jetbox · jetbox cms16 May 2007

  • CVE-2007-1898
    24İzleyin

    formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_host

    OrtaCVSS 5,8Kavram kanıtıEPSS %3

    hp · hp-ux16 May 2007

  • CVE-2007-2733
    24İzleyin

    Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts vi

    OrtaCVSS 6,0İstismar yokEPSS %1

    jetbox · jetbox cms16 May 2007

  • CVE-2008-4651
    24İzleyin

    Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orde

    OrtaCVSS 6,0Kavram kanıtıEPSS %1

    jetbox · jetbox cms21 Eki 2008

  • CVE-2004-1447
    21İzleyin

    Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive in

    OrtaCVSS 5,0İstismar yokEPSS %2

    jetbox · jetbox one cms31 Ara 2004

  • CVE-2007-2684
    20İzleyin

    Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and

    OrtaCVSS 5,0İstismar yokEPSS %2

    jetbox · jetbox cms21 May 2007

  • CVE-2006-4740
    20İzleyin

    Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error

    OrtaCVSS 5,0İstismar yokEPSS %1

    jetbox · jetbox cms13 Eyl 2006

  • CVE-2004-1448
    19İzleyin

    Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and exec

    OrtaCVSS 4,6İstismar yokEPSS %2

    jetbox · jetbox one cms31 Ara 2004

  • CVE-2007-2686
    18İzleyin

    Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via t

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    jetbox · jetbox cms22 May 2007

  • CVE-2006-3585
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1 SR1 allow remote attackers to inject arbitrary web script or HTML via

    OrtaCVSS 4,3İstismar yokEPSS %2

    jetbox · jetbox cms8 Ağu 2006

  • CVE-2008-6174
    17İzleyin

    Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web scr

    OrtaCVSS 4,3Kavram kanıtıEPSS %1

    jetbox · jetbox cms19 Şub 2009

  • CVE-2007-2731
    16İzleyin

    CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A)

    OrtaCVSS 4,0İstismar yokEPSS %2

    jetbox · jetbox cms16 May 2007

  • CVE-2006-4739
    10İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstr

    DüşükCVSS 2,6İstismar yokEPSS %1

    jetbox · jetbox cms13 Eyl 2006