contentcustomizer records
2 published records for vendor contentcustomizer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2007-5817Proof of concept | dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackupcontentcustomizer · contentcustomizer · CWE-79 | Medium6.1 | — | 1.0% | Nov 5, 2007 |
21Monitor | CVE-2007-5816Proof of concept | dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with ancontentcustomizer · contentcustomizer · CWE-200 | Medium5.0 | — | 2.5% | Nov 5, 2007 |
- CVE-2007-581724Monitor
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del, (2) delbackup
MediumCVSS 6.1Proof of conceptEPSS 1%contentcustomizer · contentcustomizerNov 5, 2007
- CVE-2007-581621Monitor
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an
MediumCVSS 5.0Proof of conceptEPSS 3%contentcustomizer · contentcustomizerNov 5, 2007