Skip to content
Noroxi

exv2 records

11 published records for vendor exv2.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program v

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    exv2 · content management systemMar 2, 2007

  • CVE-2007-1966
    36Monitor

    Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cooki

    CriticalCVSS 9.1No exploitEPSS 1%

    exv2 · content management systemApr 11, 2007

  • CVE-2008-1349
    30Monitor

    SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to

    HighCVSS 7.5Proof of conceptEPSS 1%

    exv2 · bamagalerieMar 17, 2008

  • CVE-2006-5030
    30Monitor

    SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary

    HighCVSS 7.5Proof of conceptEPSS 1%

    exv2 · content management systemSep 27, 2006

  • CVE-2008-1404
    27Monitor

    SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitr

    MediumCVSS 6.8Proof of conceptEPSS 1%

    exv2 · exv2Mar 20, 2008

  • CVE-2008-1407
    27Monitor

    SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via t

    MediumCVSS 6.8Proof of conceptEPSS 1%

    exv2 · exv2Mar 20, 2008

  • CVE-2008-1406
    27Monitor

    SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL comma

    MediumCVSS 6.8Proof of conceptEPSS 1%

    exv2 · exv2Mar 20, 2008

  • CVE-2006-7080
    18Monitor

    Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files

    MediumCVSS 4.3Proof of conceptEPSS 5%

    exv2 · content management systemMar 2, 2007

  • CVE-2010-4155
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (

    MediumCVSS 4.3No exploitEPSS 1%

    exv2 · exv2Nov 3, 2010

  • CVE-2007-4365
    17Monitor

    Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a

    MediumCVSS 4.3No exploitEPSS 1%

    exv2 · content management systemAug 15, 2007

  • CVE-2007-1965
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3No exploitEPSS 1%

    exv2 · content management systemApr 11, 2007