Skip to content
Noroxi

exponent records

16 published records for vendor exponent.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    16 records
    • Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not

      CriticalCVSS 10.0No exploitEPSS 2%

      exponent · exponent cmsApr 4, 2006

    • The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files

      CriticalCVSS 10.0No exploitEPSS 1%

      exponent · exponentNov 22, 2005

    • CVE-2006-1605
      31Monitor

      Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unkno

      HighCVSS 7.5No exploitEPSS 3%

      exponent · exponent cmsApr 4, 2006

    • CVE-2005-3765
      31Monitor

      Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to

      HighCVSS 7.5No exploitEPSS 3%

      exponent · exponentNov 22, 2005

    • CVE-2005-3762
      30Monitor

      SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to

      HighCVSS 7.5No exploitEPSS 1%

      exponent · exponentNov 22, 2005

    • CVE-2006-1607
      30Monitor

      Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.

      HighCVSS 7.5No exploitEPSS 1%

      exponent · exponent cmsApr 4, 2006

    • CVE-2006-4963
      27Monitor

      Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via

      MediumCVSS 6.4Proof of conceptEPSS 7%

      exponent · exponent cmsSep 23, 2006

    • CVE-2007-2252
      21Monitor

      Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive inf

      MediumCVSS 5.0Proof of conceptEPSS 3%

      exponent · exponent cmsApr 25, 2007

    • CVE-2005-0310
      21Monitor

      Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info

      MediumCVSS 5.0No exploitEPSS 2%

      exponent · exponentMay 2, 2005

    • CVE-2005-3763
      20Monitor

      Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers

      MediumCVSS 5.0No exploitEPSS 1%

      exponent · exponentNov 22, 2005

    • CVE-2005-3767
      20Monitor

      Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and e

      MediumCVSS 5.0No exploitEPSS 1%

      exponent · exponentNov 22, 2005

    • CVE-2007-2253
      20Monitor

      Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol

      MediumCVSS 5.0No exploitEPSS 1%

      exponent · exponent cmsApr 25, 2007

    • CVE-2006-1606
      20Monitor

      Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.

      MediumCVSS 5.0No exploitEPSS 1%

      exponent · exponent cmsApr 4, 2006

    • CVE-2005-3766
      20Monitor

      Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though

      MediumCVSS 5.0No exploitEPSS 1%

      exponent · exponentNov 22, 2005

    • CVE-2005-0309
      17Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitr

      MediumCVSS 4.3No exploitEPSS 1%

      exponent · exponentJan 25, 2005

    • CVE-2005-3761
      17Monitor

      Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or

      MediumCVSS 4.3No exploitEPSS 1%

      exponent · exponentNov 22, 2005