dotbr records
3 published records for vendor dotbr.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2003-1405Proof of concept | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.dotbr · botbr · CWE-20 | High7.5 | — | 4.0% | Dec 31, 2003 |
30Monitor | CVE-2003-1403No exploit | foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.dotbr · botbr · CWE-20 | High7.5 | — | 1.5% | Dec 31, 2003 |
30Monitor | CVE-2003-1404No exploit | DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive dotbr · botbr · CWE-200 | High7.5 | — | 1.4% | Dec 31, 2003 |
- CVE-2003-140531Monitor
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
HighCVSS 7.5Proof of conceptEPSS 4%dotbr · botbrDec 31, 2003
- CVE-2003-140330Monitor
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
HighCVSS 7.5No exploitEPSS 1%dotbr · botbrDec 31, 2003
- CVE-2003-140430Monitor
DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive
HighCVSS 7.5No exploitEPSS 1%dotbr · botbrDec 31, 2003