Xoops kayıtları
xoops üreticisine ait 101 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 52
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')26
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
101 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2007-3236Kavram kanıtı | PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHPxoops · horoscope module | Yüksek7,5 | — | %77,0 | 14 Haz 2007 |
48Planlayın | CVE-2007-3057Kavram kanıtı | PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackexoops · icontent module | Orta6,8 | — | %68,7 | 5 Haz 2007 |
47Planlayın | CVE-2007-3221Kavram kanıtı | PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to xoops · xt-conteudo module | Orta6,8 | — | %67,8 | 14 Haz 2007 |
47Planlayın | CVE-2007-3237Kavram kanıtı | PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackersxoops · tinycontent module | Orta6,8 | — | %67,7 | 14 Haz 2007 |
46Planlayın | CVE-2007-3220Kavram kanıtı | PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackexoops · cjay content module | Orta6,8 | — | %62,7 | 14 Haz 2007 |
39İzleyin | CVE-2017-11174İstismar yok | In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL xoops · xoops · CWE-89 | Kritik9,8 | — | %1,0 | 12 Tem 2017 |
36İzleyin | CVE-2023-36217İstismar yok | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of txoops · xoops · CWE-79 | Kritik9,0 | — | %1,6 | 3 Ağu 2023 |
34İzleyin | CVE-2007-3289Kavram kanıtı | PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to executxoops · wiwimod module | Yüksek7,5 | — | %12,2 | 20 Haz 2007 |
32İzleyin | CVE-2007-3222Kavram kanıtı | PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHxoops · xfsection module | Yüksek7,5 | — | %7,4 | 14 Haz 2007 |
32İzleyin | CVE-2008-3296Kavram kanıtı | Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary locxoops · xoops · CWE-22 | Yüksek7,5 | — | %5,7 | 25 Tem 2008 |
32İzleyin | CVE-2007-1974Kavram kanıtı | SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modulwf-sections · wf-sections | Yüksek7,5 | — | %5,5 | 11 Nis 2007 |
31İzleyin | CVE-2007-2370Kavram kanıtı | SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrarxoops · john mordo jobs module | Yüksek7,5 | — | %2,9 | 30 Nis 2007 |
31İzleyin | CVE-2008-0612Kavram kanıtı | Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary localxoops · xoops · CWE-22 | Yüksek7,5 | — | %2,8 | 6 Şub 2008 |
31İzleyin | CVE-2007-5188İstismar yok | Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vixoops · xoops | Yüksek7,5 | — | %2,4 | 3 Eki 2007 |
31İzleyin | CVE-2007-1838Kavram kanıtı | SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQxoops · friendfinder module | Yüksek7,5 | — | %2,2 | 2 Nis 2007 |
31İzleyin | CVE-2007-1979Kavram kanıtı | SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQxoops · xoops popnupblog | Yüksek7,5 | — | %2,2 | 11 Nis 2007 |
31İzleyin | CVE-2007-1846Kavram kanıtı | SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL cxoops · malaika system myads module | Yüksek7,5 | — | %2,2 | 3 Nis 2007 |
31İzleyin | CVE-2008-7178Kavram kanıtı | Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..xoops · xoops · CWE-22 | Yüksek7,5 | — | %2,2 | 8 Eyl 2009 |
31İzleyin | CVE-2007-0377İstismar yok | Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in xoops · xoops | Yüksek7,5 | — | %2,1 | 19 Oca 2007 |
31İzleyin | CVE-2014-3935Kavram kanıtı | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commxoops · glossaire module · CWE-89 | Yüksek7,5 | — | %2,1 | 2 Haz 2014 |
31İzleyin | CVE-2007-1976İstismar yok | PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute xoops · xoops virii info module | Yüksek7,5 | — | %2,0 | 11 Nis 2007 |
31İzleyin | CVE-2002-0217İstismar yok | Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on oxoops · xoops | Yüksek7,5 | — | %1,8 | 16 May 2002 |
31İzleyin | CVE-2006-4417İstismar yok | SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avxoops · xoops | Yüksek7,5 | — | %1,7 | 28 Ağu 2006 |
31İzleyin | CVE-2009-4698Kavram kanıtı | Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commanxoops · xoops · CWE-89 | Yüksek7,5 | — | %1,7 | 15 Mar 2010 |
30İzleyin | CVE-2009-3963İstismar yok | Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.xoops · xoops | Yüksek7,5 | — | %1,6 | 17 Kas 2009 |
- CVE-2007-323653Planlayın
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP
YüksekCVSS 7,5Kavram kanıtıEPSS %77xoops · horoscope module14 Haz 2007
- CVE-2007-305748Planlayın
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attacke
OrtaCVSS 6,8Kavram kanıtıEPSS %69xoops · icontent module5 Haz 2007
- CVE-2007-322147Planlayın
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to
OrtaCVSS 6,8Kavram kanıtıEPSS %68xoops · xt-conteudo module14 Haz 2007
- CVE-2007-323747Planlayın
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers
OrtaCVSS 6,8Kavram kanıtıEPSS %68xoops · tinycontent module14 Haz 2007
- CVE-2007-322046Planlayın
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attacke
OrtaCVSS 6,8Kavram kanıtıEPSS %63xoops · cjay content module14 Haz 2007
- CVE-2017-1117439İzleyin
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL
KritikCVSS 9,8İstismar yokEPSS %1xoops · xoops12 Tem 2017
- CVE-2023-3621736İzleyin
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of t
KritikCVSS 9,0İstismar yokEPSS %2xoops · xoops3 Ağu 2023
- CVE-2007-328934İzleyin
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execut
YüksekCVSS 7,5Kavram kanıtıEPSS %12xoops · wiwimod module20 Haz 2007
- CVE-2007-322232İzleyin
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PH
YüksekCVSS 7,5Kavram kanıtıEPSS %7xoops · xfsection module14 Haz 2007
- CVE-2008-329632İzleyin
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary loc
YüksekCVSS 7,5Kavram kanıtıEPSS %6xoops · xoops25 Tem 2008
- CVE-2007-197432İzleyin
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modul
YüksekCVSS 7,5Kavram kanıtıEPSS %6wf-sections · wf-sections11 Nis 2007
- CVE-2007-237031İzleyin
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrar
YüksekCVSS 7,5Kavram kanıtıEPSS %3xoops · john mordo jobs module30 Nis 2007
- CVE-2008-061231İzleyin
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local
YüksekCVSS 7,5Kavram kanıtıEPSS %3xoops · xoops6 Şub 2008
- CVE-2007-518831İzleyin
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vi
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops3 Eki 2007
- CVE-2007-183831İzleyin
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · friendfinder module2 Nis 2007
- CVE-2007-197931İzleyin
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · xoops popnupblog11 Nis 2007
- CVE-2007-184631İzleyin
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL c
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · malaika system myads module3 Nis 2007
- CVE-2008-717831İzleyin
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · xoops8 Eyl 2009
- CVE-2007-037731İzleyin
Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops19 Oca 2007
- CVE-2014-393531İzleyin
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL comm
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · glossaire module2 Haz 2014
- CVE-2007-197631İzleyin
PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops virii info module11 Nis 2007
- CVE-2002-021731İzleyin
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on o
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops16 May 2002
- CVE-2006-441731İzleyin
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_av
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops28 Ağu 2006
- CVE-2009-469831İzleyin
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5Kavram kanıtıEPSS %2xoops · xoops15 Mar 2010
- CVE-2009-396330İzleyin
Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
YüksekCVSS 7,5İstismar yokEPSS %2xoops · xoops17 Kas 2009