jaws records
9 published records for vendor jaws.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2004-2443Proof of concept | Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash ofjaws · jaws | High7.5 | — | 8.8% | Dec 31, 2004 |
31Monitor | CVE-2006-3292Proof of concept | SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with thjaws · jaws | High7.5 | — | 4.7% | Jun 28, 2006 |
31Monitor | CVE-2004-2067Proof of concept | SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitjaws · jaws | High7.5 | — | 2.8% | Jul 29, 2004 |
28Monitor | CVE-2009-0645Proof of concept | Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a ..jaws · jaws · CWE-22 | Medium6.5 | — | 6.3% | Feb 18, 2009 |
23Monitor | CVE-2004-2445Proof of concept | Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..jaws · jaws | Medium5.0 | — | 8.4% | Dec 31, 2004 |
21Monitor | CVE-2005-2179No exploit | PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code viajaws · jaws | Medium5.0 | — | 2.1% | Jul 11, 2005 |
19Monitor | CVE-2005-3955Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other prblogbuddies · blogbuddies · CWE-79 | Medium4.3 | — | 5.6% | Dec 1, 2005 |
18Monitor | CVE-2004-2444Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the actjaws · jaws | Medium4.3 | — | 4.2% | Dec 31, 2004 |
18Monitor | CVE-2005-1231No exploit | Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrarjaws · jaws | Medium4.3 | — | 1.9% | May 2, 2005 |
- CVE-2004-244333Monitor
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of
HighCVSS 7.5Proof of conceptEPSS 9%jaws · jawsDec 31, 2004
- CVE-2006-329231Monitor
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with th
HighCVSS 7.5Proof of conceptEPSS 5%jaws · jawsJun 28, 2006
- CVE-2004-206731Monitor
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbit
HighCVSS 7.5Proof of conceptEPSS 3%jaws · jawsJul 29, 2004
- CVE-2009-064528Monitor
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a ..
MediumCVSS 6.5Proof of conceptEPSS 6%jaws · jawsFeb 18, 2009
- CVE-2004-244523Monitor
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 8%jaws · jawsDec 31, 2004
- CVE-2005-217921Monitor
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via
MediumCVSS 5.0No exploitEPSS 2%jaws · jawsJul 11, 2005
- CVE-2005-395519Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other pr
MediumCVSS 4.3Proof of conceptEPSS 6%blogbuddies · blogbuddiesDec 1, 2005
- CVE-2004-244418Monitor
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the act
MediumCVSS 4.3Proof of conceptEPSS 4%jaws · jawsDec 31, 2004
- CVE-2005-123118Monitor
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrar
MediumCVSS 4.3No exploitEPSS 2%jaws · jawsMay 2, 2005