ens records
7 published records for vendor ens.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2018-19510No exploit | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.ens · webgalamb · CWE-89 | Critical9.8 | — | 20.0% | Mar 21, 2019 |
40Plan | CVE-2018-19514No exploit | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.ens · webgalamb · CWE-434 | Critical9.8 | — | 4.9% | Mar 21, 2019 |
40Plan | CVE-2018-19515No exploit | In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.ens · webgalamb · CWE-863 | Critical9.8 | — | 2.9% | Mar 21, 2019 |
31Monitor | CVE-2018-19513No exploit | In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenens · webgalamb · CWE-532 | High7.5 | — | 2.1% | Mar 21, 2019 |
30Monitor | CVE-2018-19512No exploit | In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by auens · webgalamb · CWE-22 | High7.2 | — | 7.2% | Mar 21, 2019 |
26Monitor | CVE-2018-19511No exploit | wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator pens · webgalamb · CWE-352 | Medium6.5 | — | 0.7% | Mar 21, 2019 |
24Monitor | CVE-2018-19509No exploit | wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodinens · webgalamb · CWE-79 | Medium6.1 | — | 1.1% | Mar 21, 2019 |
- CVE-2018-1951045Plan
subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.
CriticalCVSS 9.8No exploitEPSS 20%ens · webgalambMar 21, 2019
- CVE-2018-1951440Plan
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.
CriticalCVSS 9.8No exploitEPSS 5%ens · webgalambMar 21, 2019
- CVE-2018-1951540Plan
In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.
CriticalCVSS 9.8No exploitEPSS 3%ens · webgalambMar 21, 2019
- CVE-2018-1951331Monitor
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filen
HighCVSS 7.5No exploitEPSS 2%ens · webgalambMar 21, 2019
- CVE-2018-1951230Monitor
In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by au
HighCVSS 7.2No exploitEPSS 7%ens · webgalambMar 21, 2019
- CVE-2018-1951126Monitor
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator p
MediumCVSS 6.5No exploitEPSS 1%ens · webgalambMar 21, 2019
- CVE-2018-1950924Monitor
wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodin
MediumCVSS 6.1No exploitEPSS 1%ens · webgalambMar 21, 2019