eqdkp records
9 published records for vendor eqdkp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2007-0760Proof of concept | EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which alloweqdkp · eqdkp | High7.5 | — | 2.5% | Feb 5, 2007 |
30Monitor | CVE-2005-2615No exploit | Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.eqdkp · eqdkp | High7.5 | — | 1.3% | Aug 17, 2005 |
30Monitor | CVE-2007-3077Proof of concept | SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the eqdkp · eqdkp | High7.5 | — | 1.2% | Jun 6, 2007 |
30Monitor | CVE-2008-2222Proof of concept | SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameteqdkp · eqdkp · CWE-89 | High7.5 | — | 1.1% | May 14, 2008 |
28Monitor | CVE-2007-2716Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTMeqdkp · eqdkp | Medium6.8 | — | 4.2% | May 16, 2007 |
28Monitor | CVE-2007-3079No exploit | listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which eqdkp · eqdkp | High7.1 | — | 1.2% | Jun 6, 2007 |
27Monitor | CVE-2006-2256Proof of concept | PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP codeqdkp · eqdkp | Medium6.4 | — | 7.3% | May 9, 2006 |
27Monitor | CVE-2007-4176No exploit | Multiple unspecified vulnerabilities in EQDKP Plus before 0.4.4.5 have unknown impact and attack vectors.eqdkp · eqdkp plus | Medium6.8 | — | 1.0% | Aug 7, 2007 |
17Monitor | CVE-2007-3067No exploit | Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to injeeqdkp · attunement and key | Medium4.3 | — | 1.1% | Jun 5, 2007 |
- CVE-2007-076031Monitor
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allow
HighCVSS 7.5Proof of conceptEPSS 3%eqdkp · eqdkpFeb 5, 2007
- CVE-2005-261530Monitor
Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.
HighCVSS 7.5No exploitEPSS 1%eqdkp · eqdkpAug 17, 2005
- CVE-2007-307730Monitor
SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%eqdkp · eqdkpJun 6, 2007
- CVE-2008-222230Monitor
SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id paramet
HighCVSS 7.5Proof of conceptEPSS 1%eqdkp · eqdkpMay 14, 2008
- CVE-2007-271628Monitor
Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTM
MediumCVSS 6.8Proof of conceptEPSS 4%eqdkp · eqdkpMay 16, 2007
- CVE-2007-307928Monitor
listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which
HighCVSS 7.1No exploitEPSS 1%eqdkp · eqdkpJun 6, 2007
- CVE-2006-225627Monitor
PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP cod
MediumCVSS 6.4Proof of conceptEPSS 7%eqdkp · eqdkpMay 9, 2006
- CVE-2007-417627Monitor
Multiple unspecified vulnerabilities in EQDKP Plus before 0.4.4.5 have unknown impact and attack vectors.
MediumCVSS 6.8No exploitEPSS 1%eqdkp · eqdkp plusAug 7, 2007
- CVE-2007-306717Monitor
Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inje
MediumCVSS 4.3No exploitEPSS 1%eqdkp · attunement and keyJun 5, 2007