ark-web records
5 published records for vendor ark-web.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2017-10898No exploit | SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQLark-web · a-member · CWE-89 | Critical9.8 | — | 1.3% | Dec 1, 2017 |
39Monitor | CVE-2017-10899No exploit | SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary Sark-web · a-reserve · CWE-89 | Critical9.8 | — | 1.3% | Dec 1, 2017 |
24Monitor | CVE-2022-38972No exploit | Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3ark-web · a-form · CWE-79 | Medium6.1 | — | 1.0% | Sep 11, 2022 |
22Monitor | CVE-2011-2676No exploit | The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not reqark-web · a-form · CWE-287 | Medium5.5 | — | 1.3% | Nov 3, 2011 |
17Monitor | CVE-2011-4274No exploit | Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to injeark-web · a-form pc · CWE-79 | Medium4.3 | — | 1.0% | Nov 3, 2011 |
- CVE-2017-1089839Monitor
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL
CriticalCVSS 9.8No exploitEPSS 1%ark-web · a-memberDec 1, 2017
- CVE-2017-1089939Monitor
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary S
CriticalCVSS 9.8No exploitEPSS 1%ark-web · a-reserveDec 1, 2017
- CVE-2022-3897224Monitor
Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3
MediumCVSS 6.1No exploitEPSS 1%ark-web · a-formSep 11, 2022
- CVE-2011-267622Monitor
The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not req
MediumCVSS 5.5No exploitEPSS 1%ark-web · a-formNov 3, 2011
- CVE-2011-427417Monitor
Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inje
MediumCVSS 4.3No exploitEPSS 1%ark-web · a-form pcNov 3, 2011