nexusphp project kayıtları
nexusphp project üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2017-12776İstismar yok | SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport paramnexusphp project · nexusphp · CWE-89 | Kritik9,8 | — | %1,4 | 18 Ağu 2017 |
39İzleyin | CVE-2017-12909İstismar yok | SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parametenexusphp project · nexusphp · CWE-89 | Kritik9,8 | — | %1,4 | 17 Ağu 2017 |
39İzleyin | CVE-2017-12910İstismar yok | SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.nexusphp project · nexusphp · CWE-89 | Kritik9,8 | — | %1,3 | 17 Ağu 2017 |
39İzleyin | CVE-2017-12908İstismar yok | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr paranexusphp project · nexusphp · CWE-89 | Kritik9,8 | — | %1,3 | 17 Ağu 2017 |
39İzleyin | CVE-2017-14512İstismar yok | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability thnexusphp project · nexusphp · CWE-89 | Kritik9,8 | — | %1,1 | 17 Eyl 2017 |
35İzleyin | CVE-2017-12838İstismar yok | Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests tnexusphp project · nexusphp · CWE-352 | Yüksek8,8 | — | %0,6 | 7 Eyl 2017 |
24İzleyin | CVE-2017-12792Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administranexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %1,2 | 2 Eki 2017 |
24İzleyin | CVE-2017-15305İstismar yok | XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,9 | 14 Eki 2017 |
24İzleyin | CVE-2017-12906İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_Inexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,8 | 7 Eyl 2017 |
24İzleyin | CVE-2017-14347İstismar yok | NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 12 Eyl 2017 |
24İzleyin | CVE-2017-12680İstismar yok | Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 18 Ağu 2017 |
24İzleyin | CVE-2017-12907İstismar yok | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 17 Ağu 2017 |
24İzleyin | CVE-2017-12798İstismar yok | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 10 Ağu 2017 |
24İzleyin | CVE-2017-12655İstismar yok | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 7 Ağu 2017 |
24İzleyin | CVE-2017-14534İstismar yok | Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,7 | 18 Eyl 2017 |
24İzleyin | CVE-2017-12777İstismar yok | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.nexusphp project · nexusphp · CWE-79 | Orta6,1 | — | %0,6 | 9 Ağu 2017 |
- CVE-2017-1277639İzleyin
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport param
KritikCVSS 9,8İstismar yokEPSS %1nexusphp project · nexusphp18 Ağu 2017
- CVE-2017-1290939İzleyin
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid paramete
KritikCVSS 9,8İstismar yokEPSS %1nexusphp project · nexusphp17 Ağu 2017
- CVE-2017-1291039İzleyin
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.
KritikCVSS 9,8İstismar yokEPSS %1nexusphp project · nexusphp17 Ağu 2017
- CVE-2017-1290839İzleyin
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr para
KritikCVSS 9,8İstismar yokEPSS %1nexusphp project · nexusphp17 Ağu 2017
- CVE-2017-1451239İzleyin
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability th
KritikCVSS 9,8İstismar yokEPSS %1nexusphp project · nexusphp17 Eyl 2017
- CVE-2017-1283835İzleyin
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests t
YüksekCVSS 8,8İstismar yokEPSS %1nexusphp project · nexusphp7 Eyl 2017
- CVE-2017-1279224İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administra
OrtaCVSS 6,1Kavram kanıtıEPSS %1nexusphp project · nexusphp2 Eki 2017
- CVE-2017-1530524İzleyin
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp14 Eki 2017
- CVE-2017-1290624İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_I
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp7 Eyl 2017
- CVE-2017-1434724İzleyin
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp12 Eyl 2017
- CVE-2017-1268024İzleyin
Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp18 Ağu 2017
- CVE-2017-1290724İzleyin
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp17 Ağu 2017
- CVE-2017-1279824İzleyin
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp10 Ağu 2017
- CVE-2017-1265524İzleyin
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp7 Ağu 2017
- CVE-2017-1453424İzleyin
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp18 Eyl 2017
- CVE-2017-1277724İzleyin
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
OrtaCVSS 6,1İstismar yokEPSS %1nexusphp project · nexusphp9 Ağu 2017