abweb records
3 published records for vendor abweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-6613Proof of concept | uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a dabweb · minimal-ablog · CWE-264 | High7.5 | — | 2.4% | Apr 6, 2009 |
30Monitor | CVE-2008-6611Proof of concept | SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameterabweb · minimal ablog · CWE-89 | High7.5 | — | 1.2% | Apr 6, 2009 |
28Monitor | CVE-2008-6612Proof of concept | Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploaabweb · minimal-ablog · CWE-94 | Medium6.8 | — | 3.4% | Apr 6, 2009 |
- CVE-2008-661331Monitor
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a d
HighCVSS 7.5Proof of conceptEPSS 2%abweb · minimal-ablogApr 6, 2009
- CVE-2008-661130Monitor
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter
HighCVSS 7.5Proof of conceptEPSS 1%abweb · minimal ablogApr 6, 2009
- CVE-2008-661228Monitor
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploa
MediumCVSS 6.8Proof of conceptEPSS 3%abweb · minimal-ablogApr 6, 2009