exponent records
16 published records for vendor exponent.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2006-1604No exploit | Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not exponent · exponent cms | Critical10.0 | — | 1.7% | Apr 4, 2006 |
40Plan | CVE-2005-3764No exploit | The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded filesexponent · exponent | Critical10.0 | — | 1.4% | Nov 22, 2005 |
31Monitor | CVE-2006-1605No exploit | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknoexponent · exponent cms | High7.5 | — | 2.8% | Apr 4, 2006 |
31Monitor | CVE-2005-3765No exploit | Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers toexponent · exponent | High7.5 | — | 2.7% | Nov 22, 2005 |
30Monitor | CVE-2005-3762No exploit | SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers toexponent · exponent | High7.5 | — | 1.5% | Nov 22, 2005 |
30Monitor | CVE-2006-1607No exploit | Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.exponent · exponent cms | High7.5 | — | 1.5% | Apr 4, 2006 |
27Monitor | CVE-2006-4963Proof of concept | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via exponent · exponent cms | Medium6.4 | — | 7.0% | Sep 23, 2006 |
21Monitor | CVE-2007-2252Proof of concept | Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive infexponent · exponent cms | Medium5.0 | — | 2.8% | Apr 25, 2007 |
21Monitor | CVE-2005-0310No exploit | Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.infoexponent · exponent | Medium5.0 | — | 1.7% | May 2, 2005 |
20Monitor | CVE-2005-3763No exploit | Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackersexponent · exponent | Medium5.0 | — | 1.4% | Nov 22, 2005 |
20Monitor | CVE-2005-3767No exploit | Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and eexponent · exponent | Medium5.0 | — | 1.4% | Nov 22, 2005 |
20Monitor | CVE-2007-2253No exploit | Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrolexponent · exponent cms · CWE-200 | Medium5.0 | — | 1.3% | Apr 25, 2007 |
20Monitor | CVE-2006-1606No exploit | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.exponent · exponent cms | Medium5.0 | — | 1.2% | Apr 4, 2006 |
20Monitor | CVE-2005-3766No exploit | Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though exponent · exponent | Medium5.0 | — | 1.2% | Nov 22, 2005 |
17Monitor | CVE-2005-0309No exploit | Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrexponent · exponent | Medium4.3 | — | 1.2% | Jan 25, 2005 |
17Monitor | CVE-2005-3761No exploit | Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script orexponent · exponent | Medium4.3 | — | 1.2% | Nov 22, 2005 |
- CVE-2006-160441Plan
Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not
CriticalCVSS 10.0No exploitEPSS 2%exponent · exponent cmsApr 4, 2006
- CVE-2005-376440Plan
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files
CriticalCVSS 10.0No exploitEPSS 1%exponent · exponentNov 22, 2005
- CVE-2006-160531Monitor
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unkno
HighCVSS 7.5No exploitEPSS 3%exponent · exponent cmsApr 4, 2006
- CVE-2005-376531Monitor
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to
HighCVSS 7.5No exploitEPSS 3%exponent · exponentNov 22, 2005
- CVE-2005-376230Monitor
SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to
HighCVSS 7.5No exploitEPSS 1%exponent · exponentNov 22, 2005
- CVE-2006-160730Monitor
Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.
HighCVSS 7.5No exploitEPSS 1%exponent · exponent cmsApr 4, 2006
- CVE-2006-496327Monitor
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via
MediumCVSS 6.4Proof of conceptEPSS 7%exponent · exponent cmsSep 23, 2006
- CVE-2007-225221Monitor
Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive inf
MediumCVSS 5.0Proof of conceptEPSS 3%exponent · exponent cmsApr 25, 2007
- CVE-2005-031021Monitor
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info
MediumCVSS 5.0No exploitEPSS 2%exponent · exponentMay 2, 2005
- CVE-2005-376320Monitor
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 1%exponent · exponentNov 22, 2005
- CVE-2005-376720Monitor
Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and e
MediumCVSS 5.0No exploitEPSS 1%exponent · exponentNov 22, 2005
- CVE-2007-225320Monitor
Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol
MediumCVSS 5.0No exploitEPSS 1%exponent · exponent cmsApr 25, 2007
- CVE-2006-160620Monitor
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.
MediumCVSS 5.0No exploitEPSS 1%exponent · exponent cmsApr 4, 2006
- CVE-2005-376620Monitor
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though
MediumCVSS 5.0No exploitEPSS 1%exponent · exponentNov 22, 2005
- CVE-2005-030917Monitor
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitr
MediumCVSS 4.3No exploitEPSS 1%exponent · exponentJan 25, 2005
- CVE-2005-376117Monitor
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 1%exponent · exponentNov 22, 2005