comdev records
16 published records for vendor comdev.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 13
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-6368Proof of concept | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.comdev · jomestate pro · CWE-89 | Critical9.8 | — | 2.7% | Feb 17, 2018 |
40Plan | CVE-2007-2422No exploit | Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute comdev · modules builder | Critical9.8 | — | 2.4% | May 1, 2007 |
32Monitor | CVE-2006-5101No exploit | PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, comdev · comdev csv importer · CWE-94 | High7.5 | — | 6.1% | Oct 3, 2006 |
30Monitor | CVE-2006-5439No exploit | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Misc Tools 4.1, when register_globals is enabled, allows remote attackerscomdev · comdev misc tools · CWE-94 | High7.5 | — | 1.5% | Oct 20, 2006 |
30Monitor | CVE-2006-5441No exploit | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackercomdev · comdev web blogger | High7.5 | — | 1.5% | Oct 20, 2006 |
30Monitor | CVE-2006-5438No exploit | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to ecomdev · comdev forum | High7.5 | — | 1.5% | Oct 20, 2006 |
30Monitor | CVE-2006-5440No exploit | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attackcomdev · comdev form designer | High7.5 | — | 1.5% | Oct 20, 2006 |
30Monitor | CVE-2007-3081No exploit | PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP codecomdev · comdev ecommerce | High7.5 | — | 1.4% | Jun 6, 2007 |
30Monitor | CVE-2007-3084No exploit | PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP codecomdev · comdev web blogger | High7.5 | — | 1.3% | Jun 6, 2007 |
30Monitor | CVE-2005-3825Proof of concept | SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands viacomdev · comdev vote caster | High7.5 | — | 1.2% | Nov 25, 2005 |
30Monitor | CVE-2008-1872Proof of concept | SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via thcomdev · comdev news publisher · CWE-89 | High7.5 | — | 1.0% | Apr 17, 2008 |
28Monitor | CVE-2006-6045Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URcomdev · comdev one admin pro | Medium6.8 | — | 2.8% | Nov 21, 2006 |
27Monitor | CVE-2008-6250Proof of concept | SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmoncomdev · comdev web blogger · CWE-89 | Medium6.8 | — | 1.1% | Feb 23, 2009 |
22Monitor | CVE-2005-2543Proof of concept | Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a ..comdev · comdev ecommerce | Medium5.0 | — | 6.0% | Aug 10, 2005 |
20Monitor | CVE-2005-2544No exploit | PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the comdev · comdev ecommerce | Medium5.0 | — | 1.5% | Aug 10, 2005 |
17Monitor | CVE-2005-2138No exploit | Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web scriptcomdev · comdev ecommerce | Medium4.3 | — | 1.0% | Jul 5, 2005 |
- CVE-2018-636840Plan
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
CriticalCVSS 9.8Proof of conceptEPSS 3%comdev · jomestate proFeb 17, 2018
- CVE-2007-242240Plan
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute
CriticalCVSS 9.8No exploitEPSS 2%comdev · modules builderMay 1, 2007
- CVE-2006-510132Monitor
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1,
HighCVSS 7.5No exploitEPSS 6%comdev · comdev csv importerOct 3, 2006
- CVE-2006-543930Monitor
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Misc Tools 4.1, when register_globals is enabled, allows remote attackers
HighCVSS 7.5No exploitEPSS 1%comdev · comdev misc toolsOct 20, 2006
- CVE-2006-544130Monitor
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attacker
HighCVSS 7.5No exploitEPSS 1%comdev · comdev web bloggerOct 20, 2006
- CVE-2006-543830Monitor
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to e
HighCVSS 7.5No exploitEPSS 1%comdev · comdev forumOct 20, 2006
- CVE-2006-544030Monitor
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attack
HighCVSS 7.5No exploitEPSS 1%comdev · comdev form designerOct 20, 2006
- CVE-2007-308130Monitor
PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code
HighCVSS 7.5No exploitEPSS 1%comdev · comdev ecommerceJun 6, 2007
- CVE-2007-308430Monitor
PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code
HighCVSS 7.5No exploitEPSS 1%comdev · comdev web bloggerJun 6, 2007
- CVE-2005-382530Monitor
SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%comdev · comdev vote casterNov 25, 2005
- CVE-2008-187230Monitor
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 1%comdev · comdev news publisherApr 17, 2008
- CVE-2006-604528Monitor
Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a UR
MediumCVSS 6.8Proof of conceptEPSS 3%comdev · comdev one admin proNov 21, 2006
- CVE-2008-625027Monitor
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmon
MediumCVSS 6.8Proof of conceptEPSS 1%comdev · comdev web bloggerFeb 23, 2009
- CVE-2005-254322Monitor
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 6%comdev · comdev ecommerceAug 10, 2005
- CVE-2005-254420Monitor
PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the
MediumCVSS 5.0No exploitEPSS 1%comdev · comdev ecommerceAug 10, 2005
- CVE-2005-213817Monitor
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%comdev · comdev ecommerceJul 5, 2005