Skip to content
Noroxi

eva-web records

3 published records for vendor eva-web.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      Attack profile

      All records

      3 records
      • CVE-2007-3460
        31Monitor

        Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP

        HighCVSS 7.5Proof of conceptEPSS 3%

        eva-web · eva-webJun 27, 2007

      • CVE-2006-2690
        31Monitor

        An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server vi

        HighCVSS 7.8No exploitEPSS 1%

        eva-web · eva-webMay 31, 2006

      • CVE-2006-2689
        28Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HT

        MediumCVSS 6.8Proof of conceptEPSS 2%

        eva-web · eva-webMay 31, 2006