obm records
5 published records for vendor obm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2011-5141No exploit | Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote auobm · open business management · CWE-22 | Medium6.0 | — | 1.3% | Aug 31, 2012 |
22Monitor | CVE-2011-5145No exploit | Multiple SQL injection vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote authenticated users toobm · open business management · CWE-89 | Medium5.5 | — | 1.2% | Aug 31, 2012 |
20Monitor | CVE-2011-5144No exploit | Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to teobm · open business management · CWE-264 | Medium5.0 | — | 1.5% | Aug 31, 2012 |
17Monitor | CVE-2011-5142No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackersobm · open business management · CWE-79 | Medium4.3 | — | 1.2% | Aug 31, 2012 |
17Monitor | CVE-2011-5143No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.3.20 and probably earlier allow remote attackers to obm · open business management · CWE-79 | Medium4.3 | — | 0.9% | Aug 31, 2012 |
- CVE-2011-514124Monitor
Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote au
MediumCVSS 6.0No exploitEPSS 1%obm · open business managementAug 31, 2012
- CVE-2011-514522Monitor
Multiple SQL injection vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote authenticated users to
MediumCVSS 5.5No exploitEPSS 1%obm · open business managementAug 31, 2012
- CVE-2011-514420Monitor
Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to te
MediumCVSS 5.0No exploitEPSS 1%obm · open business managementAug 31, 2012
- CVE-2011-514217Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers
MediumCVSS 4.3No exploitEPSS 1%obm · open business managementAug 31, 2012
- CVE-2011-514317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.3.20 and probably earlier allow remote attackers to
MediumCVSS 4.3No exploitEPSS 1%obm · open business managementAug 31, 2012