nextweb records
3 published records for vendor nextweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2005-1834No exploit | SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authenticatnextweb · nextweb \(i\)site | High7.5 | — | 1.4% | Jun 1, 2005 |
21Monitor | CVE-2005-1835No exploit | NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensinextweb · nextweb \(i\)site · CWE-552 | Medium5.0 | — | 2.0% | Jun 1, 2005 |
21Monitor | CVE-2005-1836No exploit | NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard reqnextweb · nextweb \(i\)site | Medium5.0 | — | 1.8% | Jun 1, 2005 |
- CVE-2005-183430Monitor
SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authenticat
HighCVSS 7.5No exploitEPSS 1%nextweb · nextweb \(i\)siteJun 1, 2005
- CVE-2005-183521Monitor
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensi
MediumCVSS 5.0No exploitEPSS 2%nextweb · nextweb \(i\)siteJun 1, 2005
- CVE-2005-183621Monitor
NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard req
MediumCVSS 5.0No exploitEPSS 2%nextweb · nextweb \(i\)siteJun 1, 2005