uapplication records
13 published records for vendor uapplication.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2005-1427No exploit | Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information viuapplication · uphotogallery | High7.5 | — | 1.7% | May 3, 2005 |
30Monitor | CVE-2005-1428No exploit | edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.uapplication · uphotogallery | High7.5 | — | 1.5% | May 3, 2005 |
30Monitor | CVE-2006-6247Proof of concept | Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ciuapplication · uphotogallery | High7.5 | — | 1.2% | Dec 4, 2006 |
30Monitor | CVE-2007-0799No exploit | SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vuapplication · ublog | High7.5 | — | 1.2% | Feb 6, 2007 |
23Monitor | CVE-2006-2246No exploit | Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via textuapplication · ublog | Medium5.8 | — | 1.5% | May 9, 2006 |
20Monitor | CVE-2005-1425No exploit | Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers uapplication · uguestbook · CWE-264 | Medium5.0 | — | 1.5% | May 3, 2005 |
20Monitor | CVE-2005-1426No exploit | Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers touapplication · ublog · CWE-264 | Medium5.0 | — | 1.5% | May 3, 2005 |
20Monitor | CVE-2005-0938No exploit | Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passworuapplication · ublog reload | Medium5.0 | — | 1.4% | May 2, 2005 |
18Monitor | CVE-2005-2010Proof of concept | Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTuapplication · ublog reload | Medium4.3 | — | 3.6% | Jun 20, 2005 |
18Monitor | CVE-2007-0798No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via uapplication · ublog reload | Medium4.3 | — | 2.0% | Feb 6, 2007 |
18Monitor | CVE-2005-0925Proof of concept | Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web scruapplication · ublog reload | Medium4.3 | — | 2.0% | May 2, 2005 |
18Monitor | CVE-2006-3023No exploit | Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers tuapplication · uphotogallery | Medium4.3 | — | 1.8% | Jun 15, 2006 |
17Monitor | CVE-2007-0815No exploit | Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators uapplication · uphotogallery | Medium4.3 | — | 1.1% | Feb 7, 2007 |
- CVE-2005-142731Monitor
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information vi
HighCVSS 7.5No exploitEPSS 2%uapplication · uphotogalleryMay 3, 2005
- CVE-2005-142830Monitor
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.
HighCVSS 7.5No exploitEPSS 1%uapplication · uphotogalleryMay 3, 2005
- CVE-2006-624730Monitor
Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci
HighCVSS 7.5Proof of conceptEPSS 1%uapplication · uphotogalleryDec 4, 2006
- CVE-2007-079930Monitor
SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified v
HighCVSS 7.5No exploitEPSS 1%uapplication · ublogFeb 6, 2007
- CVE-2006-224623Monitor
Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text
MediumCVSS 5.8No exploitEPSS 1%uapplication · ublogMay 9, 2006
- CVE-2005-142520Monitor
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 2%uapplication · uguestbookMay 3, 2005
- CVE-2005-142620Monitor
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to
MediumCVSS 5.0No exploitEPSS 2%uapplication · ublogMay 3, 2005
- CVE-2005-093820Monitor
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwor
MediumCVSS 5.0No exploitEPSS 1%uapplication · ublog reloadMay 2, 2005
- CVE-2005-201018Monitor
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HT
MediumCVSS 4.3Proof of conceptEPSS 4%uapplication · ublog reloadJun 20, 2005
- CVE-2007-079818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 2%uapplication · ublog reloadFeb 6, 2007
- CVE-2005-092518Monitor
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web scr
MediumCVSS 4.3Proof of conceptEPSS 2%uapplication · ublog reloadMay 2, 2005
- CVE-2006-302318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers t
MediumCVSS 4.3No exploitEPSS 2%uapplication · uphotogalleryJun 15, 2006
- CVE-2007-081517Monitor
Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators
MediumCVSS 4.3No exploitEPSS 1%uapplication · uphotogalleryFeb 7, 2007