Skip to content
Noroxi

jetbox records

21 published records for vendor jetbox.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

21 records
  • CVE-2006-2270
    34Monitor

    PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL

    HighCVSS 7.5Proof of conceptEPSS 14%

    jetbox · jetbox cmsMay 9, 2006

  • CVE-2006-4422
    32Monitor

    PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arb

    HighCVSS 7.5Proof of conceptEPSS 7%

    jetbox · jetbox cmsAug 28, 2006

  • CVE-2006-3583
    31Monitor

    Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator

    HighCVSS 7.5No exploitEPSS 2%

    jetbox · jetbox cmsAug 8, 2006

  • CVE-2006-3584
    30Monitor

    Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables vi

    HighCVSS 7.5No exploitEPSS 2%

    jetbox · jetbox cmsAug 8, 2006

  • CVE-2006-4738
    30Monitor

    PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the

    HighCVSS 7.5No exploitEPSS 1%

    jetbox · jetbox cmsSep 13, 2006

  • CVE-2006-3586
    30Monitor

    SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to execute arbitrary SQL commands via the (1) frontsession COOKIE

    HighCVSS 7.5No exploitEPSS 1%

    jetbox · jetbox cmsAug 8, 2006

  • CVE-2006-4737
    30Monitor

    SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter

    HighCVSS 7.5No exploitEPSS 1%

    jetbox · jetbox cmsSep 13, 2006

  • CVE-2007-2685
    30Monitor

    Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) v

    HighCVSS 7.5Proof of conceptEPSS 1%

    jetbox · jetbox cmsMay 21, 2007

  • CVE-2007-2732
    28Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1)

    MediumCVSS 6.8Proof of conceptEPSS 4%

    jetbox · jetbox cmsMay 16, 2007

  • CVE-2007-1898
    24Monitor

    formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_host

    MediumCVSS 5.8Proof of conceptEPSS 3%

    hp · hp-uxMay 16, 2007

  • CVE-2007-2733
    24Monitor

    Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts vi

    MediumCVSS 6.0No exploitEPSS 1%

    jetbox · jetbox cmsMay 16, 2007

  • CVE-2008-4651
    24Monitor

    Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orde

    MediumCVSS 6.0Proof of conceptEPSS 1%

    jetbox · jetbox cmsOct 21, 2008

  • CVE-2004-1447
    21Monitor

    Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive in

    MediumCVSS 5.0No exploitEPSS 2%

    jetbox · jetbox one cmsDec 31, 2004

  • CVE-2007-2684
    20Monitor

    Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and

    MediumCVSS 5.0No exploitEPSS 2%

    jetbox · jetbox cmsMay 21, 2007

  • CVE-2006-4740
    20Monitor

    Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error

    MediumCVSS 5.0No exploitEPSS 1%

    jetbox · jetbox cmsSep 13, 2006

  • CVE-2004-1448
    19Monitor

    Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and exec

    MediumCVSS 4.6No exploitEPSS 2%

    jetbox · jetbox one cmsDec 31, 2004

  • CVE-2007-2686
    18Monitor

    Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via t

    MediumCVSS 4.3Proof of conceptEPSS 2%

    jetbox · jetbox cmsMay 22, 2007

  • CVE-2006-3585
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1 SR1 allow remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3No exploitEPSS 2%

    jetbox · jetbox cmsAug 8, 2006

  • CVE-2008-6174
    17Monitor

    Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web scr

    MediumCVSS 4.3Proof of conceptEPSS 1%

    jetbox · jetbox cmsFeb 19, 2009

  • CVE-2007-2731
    16Monitor

    CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A)

    MediumCVSS 4.0No exploitEPSS 2%

    jetbox · jetbox cmsMay 16, 2007

  • CVE-2006-4739
    10Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstr

    LowCVSS 2.6No exploitEPSS 1%

    jetbox · jetbox cmsSep 13, 2006