Skip to content
Noroxi

jaws records

9 published records for vendor jaws.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • CVE-2004-2443
    33Monitor

    Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of

    HighCVSS 7.5Proof of conceptEPSS 9%

    jaws · jawsDec 31, 2004

  • CVE-2006-3292
    31Monitor

    SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with th

    HighCVSS 7.5Proof of conceptEPSS 5%

    jaws · jawsJun 28, 2006

  • CVE-2004-2067
    31Monitor

    SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbit

    HighCVSS 7.5Proof of conceptEPSS 3%

    jaws · jawsJul 29, 2004

  • CVE-2009-0645
    28Monitor

    Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a ..

    MediumCVSS 6.5Proof of conceptEPSS 6%

    jaws · jawsFeb 18, 2009

  • CVE-2004-2445
    23Monitor

    Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 8%

    jaws · jawsDec 31, 2004

  • CVE-2005-2179
    21Monitor

    PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via

    MediumCVSS 5.0No exploitEPSS 2%

    jaws · jawsJul 11, 2005

  • CVE-2005-3955
    19Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other pr

    MediumCVSS 4.3Proof of conceptEPSS 6%

    blogbuddies · blogbuddiesDec 1, 2005

  • CVE-2004-2444
    18Monitor

    Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the act

    MediumCVSS 4.3Proof of conceptEPSS 4%

    jaws · jawsDec 31, 2004

  • CVE-2005-1231
    18Monitor

    Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrar

    MediumCVSS 4.3No exploitEPSS 2%

    jaws · jawsMay 2, 2005