jax scripts records
6 published records for vendor jax scripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2009-4447Proof of concept | Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbojax scripts · jax guestbook · CWE-287 | High7.5 | — | 2.6% | Dec 29, 2009 |
28Monitor | CVE-2007-0335Proof of concept | Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local filjax scripts · jax petition book | Medium6.8 | — | 3.3% | Jan 17, 2007 |
28Monitor | CVE-2006-1913Proof of concept | Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrajax scripts · jax guestbook | Medium6.8 | — | 2.8% | Apr 20, 2006 |
21Monitor | CVE-2005-4880Proof of concept | Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers tjax scripts · jax guestbook · CWE-264 | Medium5.0 | — | 2.4% | Mar 31, 2009 |
17Monitor | CVE-2005-4879Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbijax scripts · jax guestbook · CWE-79 | Medium4.3 | — | 1.5% | Mar 31, 2009 |
17Monitor | CVE-2008-6562Proof of concept | Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary wejax scripts · jax linklists · CWE-79 | Medium4.3 | — | 1.2% | Mar 31, 2009 |
- CVE-2009-444731Monitor
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbo
HighCVSS 7.5Proof of conceptEPSS 3%jax scripts · jax guestbookDec 29, 2009
- CVE-2007-033528Monitor
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local fil
MediumCVSS 6.8Proof of conceptEPSS 3%jax scripts · jax petition bookJan 17, 2007
- CVE-2006-191328Monitor
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitra
MediumCVSS 6.8Proof of conceptEPSS 3%jax scripts · jax guestbookApr 20, 2006
- CVE-2005-488021Monitor
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers t
MediumCVSS 5.0Proof of conceptEPSS 2%jax scripts · jax guestbookMar 31, 2009
- CVE-2005-487917Monitor
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbi
MediumCVSS 4.3Proof of conceptEPSS 2%jax scripts · jax guestbookMar 31, 2009
- CVE-2008-656217Monitor
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary we
MediumCVSS 4.3Proof of conceptEPSS 1%jax scripts · jax linklistsMar 31, 2009