hotwebscripts records
8 published records for vendor hotwebscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-3135No exploit | Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary hotwebscripts · cms mundo | High7.5 | — | 1.9% | Jul 13, 2006 |
30Monitor | CVE-2006-2911No exploit | SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL comhotwebscripts · cms mundo | High7.5 | — | 1.4% | Jun 21, 2006 |
30Monitor | CVE-2010-4703No exploit | SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via thehotwebscripts · hotweb rentals · CWE-89 | High7.5 | — | 1.1% | Jan 20, 2011 |
30Monitor | CVE-2010-4737Proof of concept | SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via thehotwebscripts · hotweb rentals · CWE-89 | High7.5 | — | 1.0% | Feb 15, 2011 |
30Monitor | CVE-2009-3343Proof of concept | SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId paramehotwebscripts · hotweb rentals · CWE-89 | High7.5 | — | 0.9% | Sep 24, 2009 |
23Monitor | CVE-2006-2684No exploit | Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTMhotwebscripts · cms mundo | Medium5.8 | — | 1.3% | May 31, 2006 |
20Monitor | CVE-2006-2931No exploit | CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code byhotwebscripts · cms mundo | Medium5.1 | — | 1.5% | Jun 21, 2006 |
17Monitor | CVE-2006-2820No exploit | Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog Oggi 1.0 allows remote attackers to inject arbitrary web script or HTMLhotwebscripts · weblog oggi | Medium4.3 | — | 1.2% | Jun 5, 2006 |
- CVE-2006-313531Monitor
Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 2%hotwebscripts · cms mundoJul 13, 2006
- CVE-2006-291130Monitor
SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL com
HighCVSS 7.5No exploitEPSS 1%hotwebscripts · cms mundoJun 21, 2006
- CVE-2010-470330Monitor
SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5No exploitEPSS 1%hotwebscripts · hotweb rentalsJan 20, 2011
- CVE-2010-473730Monitor
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%hotwebscripts · hotweb rentalsFeb 15, 2011
- CVE-2009-334330Monitor
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parame
HighCVSS 7.5Proof of conceptEPSS 1%hotwebscripts · hotweb rentalsSep 24, 2009
- CVE-2006-268423Monitor
Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 5.8No exploitEPSS 1%hotwebscripts · cms mundoMay 31, 2006
- CVE-2006-293120Monitor
CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by
MediumCVSS 5.1No exploitEPSS 2%hotwebscripts · cms mundoJun 21, 2006
- CVE-2006-282017Monitor
Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog Oggi 1.0 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%hotwebscripts · weblog oggiJun 5, 2006