Skip to content
Noroxi

eqdkp records

9 published records for vendor eqdkp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    9 records
    • CVE-2007-0760
      31Monitor

      EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allow

      HighCVSS 7.5Proof of conceptEPSS 3%

      eqdkp · eqdkpFeb 5, 2007

    • CVE-2005-2615
      30Monitor

      Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.

      HighCVSS 7.5No exploitEPSS 1%

      eqdkp · eqdkpAug 17, 2005

    • CVE-2007-3077
      30Monitor

      SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the

      HighCVSS 7.5Proof of conceptEPSS 1%

      eqdkp · eqdkpJun 6, 2007

    • CVE-2008-2222
      30Monitor

      SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id paramet

      HighCVSS 7.5Proof of conceptEPSS 1%

      eqdkp · eqdkpMay 14, 2008

    • CVE-2007-2716
      28Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTM

      MediumCVSS 6.8Proof of conceptEPSS 4%

      eqdkp · eqdkpMay 16, 2007

    • CVE-2007-3079
      28Monitor

      listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which

      HighCVSS 7.1No exploitEPSS 1%

      eqdkp · eqdkpJun 6, 2007

    • CVE-2006-2256
      27Monitor

      PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP cod

      MediumCVSS 6.4Proof of conceptEPSS 7%

      eqdkp · eqdkpMay 9, 2006

    • CVE-2007-4176
      27Monitor

      Multiple unspecified vulnerabilities in EQDKP Plus before 0.4.4.5 have unknown impact and attack vectors.

      MediumCVSS 6.8No exploitEPSS 1%

      eqdkp · eqdkp plusAug 7, 2007

    • CVE-2007-3067
      17Monitor

      Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inje

      MediumCVSS 4.3No exploitEPSS 1%

      eqdkp · attunement and keyJun 5, 2007