Skip to content
Noroxi

bitweaver records

32 published records for vendor bitweaver.

All records

32 records
  • CVE-2012-5192
    36Monitor

    Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vi

    MediumCVSS 5.0WeaponizedEPSS 52%

    bitweaver · bitweaverJan 27, 2014

  • CVE-2007-6650
    31Monitor

    Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using

    HighCVSS 7.5Proof of conceptEPSS 3%

    bitweaver · r2 cmsJan 4, 2008

  • CVE-2009-1678
    31Monitor

    Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers

    HighCVSS 7.5Proof of conceptEPSS 2%

    bitweaver · bitweaverMay 18, 2009

  • CVE-2005-4380
    31Monitor

    Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1)

    HighCVSS 7.5Proof of conceptEPSS 2%

    bitweaver · bitweaverDec 19, 2005

  • CVE-2006-6923
    30Monitor

    SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL comma

    HighCVSS 7.5Proof of conceptEPSS 1%

    bitweaver · bitweaverJan 12, 2007

  • CVE-2007-6375
    30Monitor

    Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s

    HighCVSS 7.5Proof of conceptEPSS 1%

    bitweaver · bitweaverDec 14, 2007

  • CVE-2006-6925
    28Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 6.8Proof of conceptEPSS 2%

    bitweaver · bitweaverJan 12, 2007

  • CVE-2009-1677
    27Monitor

    Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1)

    MediumCVSS 6.5Proof of conceptEPSS 2%

    bitweaver · bitweaverMay 18, 2009

  • CVE-2007-6412
    27Monitor

    Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attack

    MediumCVSS 6.8No exploitEPSS 2%

    bitweaver · bitweaverDec 17, 2007

  • CVE-2012-5193
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 6.1Proof of conceptEPSS 2%

    bitweaver · bitweaverNov 13, 2019

  • CVE-2006-3104
    23Monitor

    users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals t

    MediumCVSS 5.0Proof of conceptEPSS 9%

    bitweaver · bitweaverJun 20, 2006

  • CVE-2006-3102
    23Monitor

    Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execu

    MediumCVSS 5.1Proof of conceptEPSS 8%

    bitweaver · bitweaverJun 20, 2006

  • CVE-2007-6651
    21Monitor

    Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourc

    MediumCVSS 5.0Proof of conceptEPSS 4%

    bitweaver · bitweaverJan 4, 2008

  • CVE-2006-6924
    21Monitor

    bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs

    MediumCVSS 5.0Proof of conceptEPSS 3%

    bitweaver · bitweaverJan 12, 2007

  • CVE-2006-3105
    21Monitor

    CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mu

    MediumCVSS 5.0Proof of conceptEPSS 3%

    bitweaver · bitweaverJun 20, 2006

  • CVE-2010-5086
    21Monitor

    Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0No exploitEPSS 2%

    bitweaver · bitweaverMar 19, 2012

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preference

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/inde

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_perso

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/perm

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021

  • A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit

    MediumCVSS 4.8No exploitEPSS 1%

    bitweaver · bitweaverMar 24, 2021