campware.org records
8 published records for vendor campware.org.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2006-5912No exploit | Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-wcampware.org · campsite | Critical10.0 | — | 1.6% | Nov 15, 2006 |
32Monitor | CVE-2009-2183Proof of concept | Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrarycampware.org · campsite · CWE-22 | High7.5 | — | 5.7% | Jun 23, 2009 |
31Monitor | CVE-2006-5911Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code vicampware.org · campsite | High7.5 | — | 4.6% | Nov 15, 2006 |
31Monitor | CVE-2006-5910Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP codecampware.org · campsite | High7.5 | — | 2.6% | Nov 15, 2006 |
31Monitor | CVE-2010-1867No exploit | SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/campware.org · campsite · CWE-89 | High7.5 | — | 2.0% | May 7, 2010 |
28Monitor | CVE-2009-2182Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in tcampware.org · campsite · CWE-94 | Medium6.8 | — | 1.7% | Jun 23, 2009 |
20Monitor | CVE-2005-4661No exploit | The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows recampware.org · campsite | Medium5.0 | — | 1.4% | Dec 31, 2005 |
18Monitor | CVE-2009-2181Proof of concept | Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitcampware.org · campsite · CWE-79 | Medium4.3 | — | 2.4% | Jun 23, 2009 |
- CVE-2006-591240Plan
Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-w
CriticalCVSS 10.0No exploitEPSS 2%campware.org · campsiteNov 15, 2006
- CVE-2009-218332Monitor
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 6%campware.org · campsiteJun 23, 2009
- CVE-2006-591131Monitor
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code vi
HighCVSS 7.5Proof of conceptEPSS 5%campware.org · campsiteNov 15, 2006
- CVE-2006-591031Monitor
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code
HighCVSS 7.5Proof of conceptEPSS 3%campware.org · campsiteNov 15, 2006
- CVE-2010-186731Monitor
SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/
HighCVSS 7.5No exploitEPSS 2%campware.org · campsiteMay 7, 2010
- CVE-2009-218228Monitor
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in t
MediumCVSS 6.8Proof of conceptEPSS 2%campware.org · campsiteJun 23, 2009
- CVE-2005-466120Monitor
The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows re
MediumCVSS 5.0No exploitEPSS 1%campware.org · campsiteDec 31, 2005
- CVE-2009-218118Monitor
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbit
MediumCVSS 4.3Proof of conceptEPSS 2%campware.org · campsiteJun 23, 2009