kohanaframework records
3 published records for vendor kohanaframework.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-310 Cryptographic Issues1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2014-8684Weaponized | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies andcodeigniter · codeigniter · CWE-310 | Critical9.8 | — | 71.7% | Sep 19, 2017 |
40Plan | CVE-2019-8979Proof of concept | Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.kohanaframework · kohana · CWE-89 | Critical9.8 | — | 3.2% | Feb 21, 2019 |
24Monitor | CVE-2016-10510No exploit | Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web sckohanaframework · kohana · CWE-79 | Medium6.1 | — | 1.7% | Aug 31, 2017 |
- CVE-2014-868461This week
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and
CriticalCVSS 9.8WeaponizedEPSS 72%codeigniter · codeigniterSep 19, 2017
- CVE-2019-897940Plan
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
CriticalCVSS 9.8Proof of conceptEPSS 3%kohanaframework · kohanaFeb 21, 2019
- CVE-2016-1051024Monitor
Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 2%kohanaframework · kohanaAug 31, 2017