Записи webmobo
5 опубликованных записей вендора webmobo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-1288Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP codewebmobo · wbnews | Критическая10,0 | — | 2,9 % | 6 мар. 2007 г. |
31Наблюдать | CVE-2009-4927Proof of concept | WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated webmobo · wbnews · CWE-287 | Высокая7,5 | — | 2,5 % | 12 июл. 2010 г. |
28Наблюдать | CVE-2009-0294Proof of concept | Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbwebmobo · wbnews · CWE-94 | Средняя6,8 | — | 1,8 % | 27 янв. 2009 г. |
20Наблюдать | CVE-2006-0241Эксплойта нет | Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name fwebmobo · wbnews | Средняя5,0 | — | 1,4 % | 17 янв. 2006 г. |
18Наблюдать | CVE-2010-1712Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrarywebmobo · wbnews · CWE-79 | Средняя4,3 | — | 1,9 % | 4 мая 2010 г. |
- CVE-2007-128841В плане
Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %webmobo · wbnews6 мар. 2007 г.
- CVE-2009-492731Наблюдать
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %webmobo · wbnews12 июл. 2010 г.
- CVE-2009-029428Наблюдать
Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arb
СредняяCVSS 6,8Proof of conceptEPSS 2 %webmobo · wbnews27 янв. 2009 г.
- CVE-2006-024120Наблюдать
Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name f
СредняяCVSS 5,0Эксплойта нетEPSS 1 %webmobo · wbnews17 янв. 2006 г.
- CVE-2010-171218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary
СредняяCVSS 4,3Proof of conceptEPSS 2 %webmobo · wbnews4 мая 2010 г.