Skip to content
Noroxi

papoo records

14 published records for vendor papoo.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface.

    HighCVSS 8.8No exploitEPSS 1%

    papoo · papooApr 13, 2021

  • CVE-2006-3572
    31Monitor

    SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5Proof of conceptEPSS 2%

    papoo · papooJul 12, 2006

  • CVE-2005-4478
    30Monitor

    Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menui

    HighCVSS 7.5Proof of conceptEPSS 1%

    papoo · papooDec 22, 2005

  • CVE-2008-3724
    30Monitor

    SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl

    HighCVSS 7.5No exploitEPSS 1%

    papoo · papooAug 20, 2008

  • CVE-2007-3453
    30Monitor

    SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid

    HighCVSS 7.5No exploitEPSS 1%

    papoo · papooJun 26, 2007

  • CVE-2007-2320
    30Monitor

    SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menui

    HighCVSS 7.5Proof of conceptEPSS 1%

    papoo · papooApr 26, 2007

  • CVE-2007-3494
    28Monitor

    Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote

    MediumCVSS 6.8No exploitEPSS 2%

    papoo · papooJun 29, 2007

  • CVE-2006-1766
    25Monitor

    Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via

    MediumCVSS 6.4No exploitEPSS 1%

    papoo · papooApr 13, 2006

  • CVE-2009-0735
    21Monitor

    Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc i

    MediumCVSS 5.1Proof of conceptEPSS 2%

    papoo · papooFeb 25, 2009

  • CVE-2014-9522
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web scrip

    MediumCVSS 4.3Proof of conceptEPSS 4%

    papoo · cms papoo lightJan 5, 2015

  • CVE-2006-0569
    17Monitor

    Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 1%

    papoo · papooFeb 7, 2006

  • CVE-2007-3269
    15Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script

    LowCVSS 3.5No exploitEPSS 2%

    papoo · papoo cms lightJun 19, 2007

  • CVE-2006-3571
    11Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitra

    LowCVSS 2.6Proof of conceptEPSS 2%

    papoo · papooJul 12, 2006

  • CVE-2006-1918
    11Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the men

    LowCVSS 2.6Proof of conceptEPSS 2%

    papoo · papooApr 20, 2006