easy-scripts records
5 published records for vendor easy-scripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2009-1664Proof of concept | myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remoteasy-scripts · answer and question script · CWE-287 | High7.5 | — | 2.0% | May 18, 2009 |
28Monitor | CVE-2009-1663Proof of concept | Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitreasy-scripts · answer and question script | Medium6.8 | — | 2.9% | May 18, 2009 |
27Monitor | CVE-2009-1655Proof of concept | Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execueasy-scripts · answer and question script · CWE-89 | Medium6.5 | — | 1.7% | May 16, 2009 |
26Monitor | CVE-2009-1665Proof of concept | myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid pareasy-scripts · answer and question script · CWE-264 | Medium6.4 | — | 2.3% | May 18, 2009 |
17Monitor | CVE-2009-1654Proof of concept | Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject easy-scripts · answer and question script · CWE-79 | Medium4.3 | — | 1.5% | May 16, 2009 |
- CVE-2009-166431Monitor
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remot
HighCVSS 7.5Proof of conceptEPSS 2%easy-scripts · answer and question scriptMay 18, 2009
- CVE-2009-166328Monitor
Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitr
MediumCVSS 6.8Proof of conceptEPSS 3%easy-scripts · answer and question scriptMay 18, 2009
- CVE-2009-165527Monitor
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execu
MediumCVSS 6.5Proof of conceptEPSS 2%easy-scripts · answer and question scriptMay 16, 2009
- CVE-2009-166526Monitor
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid par
MediumCVSS 6.4Proof of conceptEPSS 2%easy-scripts · answer and question scriptMay 18, 2009
- CVE-2009-165417Monitor
Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject
MediumCVSS 4.3Proof of conceptEPSS 1%easy-scripts · answer and question scriptMay 16, 2009