webidsupport kayıtları
webidsupport üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-697 Incorrect Comparison1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-23359İstismar yok | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Kritik9,8 | — | %1,2 | 27 Oca 2021 |
39İzleyin | CVE-2023-47397İstismar yok | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.webidsupport · webid · CWE-94 | Kritik9,8 | — | %1,0 | 8 Kas 2023 |
39İzleyin | CVE-2024-35409İstismar yok | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.webidsupport · webid · CWE-89 | Kritik9,8 | — | %0,5 | 22 May 2024 |
36İzleyin | CVE-2022-41477İstismar yok | A security issue was discovered in WeBid <=1.2.2.webidsupport · webid · CWE-918 | Kritik9,1 | — | %1,2 | 14 Eki 2022 |
35İzleyin | CVE-2018-1000867İstismar yok | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Dawebidsupport · webid · CWE-89 | Yüksek8,8 | — | %1,5 | 20 Ara 2018 |
35İzleyin | CVE-2024-32166İstismar yok | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now anwebidsupport · webid · CWE-639 | Yüksek8,8 | — | %0,7 | 19 Nis 2024 |
31İzleyin | CVE-2018-1000882İstismar yok | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fiwebidsupport · webid · CWE-22 | Yüksek7,5 | — | %2,4 | 20 Ara 2018 |
31İzleyin | CVE-2014-5114İstismar yok | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.webidsupport · webid | Yüksek7,5 | — | %2,1 | 29 Tem 2014 |
30İzleyin | CVE-2008-7116Kavram kanıtı | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commawebidsupport · webid · CWE-89 | Yüksek7,5 | — | %1,0 | 28 Ağu 2009 |
30İzleyin | CVE-2008-7119Kavram kanıtı | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id pwebidsupport · webid · CWE-89 | Yüksek7,5 | — | %1,0 | 28 Ağu 2009 |
24İzleyin | CVE-2018-1000868İstismar yok | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resulwebidsupport · webid · CWE-79 | Orta6,1 | — | %1,6 | 20 Ara 2018 |
24İzleyin | CVE-2019-11592İstismar yok | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/webidsupport · webid · CWE-79 | Orta6,1 | — | %0,8 | 29 Nis 2019 |
21İzleyin | CVE-2008-7118Kavram kanıtı | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers twebidsupport · webid · CWE-264 | Orta5,0 | — | %2,4 | 28 Ağu 2009 |
21İzleyin | CVE-2011-3815İstismar yok | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pathwebidsupport · webid · CWE-200 | Orta5,0 | — | %1,9 | 23 Eyl 2011 |
21İzleyin | CVE-2008-7117Kavram kanıtı | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requwebidsupport · webid · CWE-264 | Orta5,0 | — | %1,7 | 28 Ağu 2009 |
18İzleyin | CVE-2014-5101Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)webidsupport · webid · CWE-79 | Orta4,3 | — | %2,5 | 25 Tem 2014 |
18İzleyin | CVE-2010-4873Kavram kanıtı | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML viawebidsupport · webid · CWE-79 | Orta4,3 | — | %1,8 | 7 Eki 2011 |
- CVE-2020-2335939İzleyin
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
KritikCVSS 9,8İstismar yokEPSS %1webidsupport · webid27 Oca 2021
- CVE-2023-4739739İzleyin
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
KritikCVSS 9,8İstismar yokEPSS %1webidsupport · webid8 Kas 2023
- CVE-2024-3540939İzleyin
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
KritikCVSS 9,8İstismar yokEPSS %1webidsupport · webid22 May 2024
- CVE-2022-4147736İzleyin
A security issue was discovered in WeBid <=1.2.2.
KritikCVSS 9,1İstismar yokEPSS %1webidsupport · webid14 Eki 2022
- CVE-2018-100086735İzleyin
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da
YüksekCVSS 8,8İstismar yokEPSS %1webidsupport · webid20 Ara 2018
- CVE-2024-3216635İzleyin
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an
YüksekCVSS 8,8İstismar yokEPSS %1webidsupport · webid19 Nis 2024
- CVE-2018-100088231İzleyin
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi
YüksekCVSS 7,5İstismar yokEPSS %2webidsupport · webid20 Ara 2018
- CVE-2014-511431İzleyin
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
YüksekCVSS 7,5İstismar yokEPSS %2webidsupport · webid29 Tem 2014
- CVE-2008-711630İzleyin
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5Kavram kanıtıEPSS %1webidsupport · webid28 Ağu 2009
- CVE-2008-711930İzleyin
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p
YüksekCVSS 7,5Kavram kanıtıEPSS %1webidsupport · webid28 Ağu 2009
- CVE-2018-100086824İzleyin
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul
OrtaCVSS 6,1İstismar yokEPSS %2webidsupport · webid20 Ara 2018
- CVE-2019-1159224İzleyin
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/
OrtaCVSS 6,1İstismar yokEPSS %1webidsupport · webid29 Nis 2019
- CVE-2008-711821İzleyin
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t
OrtaCVSS 5,0Kavram kanıtıEPSS %2webidsupport · webid28 Ağu 2009
- CVE-2011-381521İzleyin
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
OrtaCVSS 5,0İstismar yokEPSS %2webidsupport · webid23 Eyl 2011
- CVE-2008-711721İzleyin
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ
OrtaCVSS 5,0Kavram kanıtıEPSS %2webidsupport · webid28 Ağu 2009
- CVE-2014-510118İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)
OrtaCVSS 4,3Kavram kanıtıEPSS %3webidsupport · webid25 Tem 2014
- CVE-2010-487318İzleyin
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3Kavram kanıtıEPSS %2webidsupport · webid7 Eki 2011