papoo records
14 published records for vendor papoo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-29054No exploit | Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface.papoo · papoo · CWE-352 | High8.8 | — | 0.8% | Apr 13, 2021 |
31Monitor | CVE-2006-3572Proof of concept | SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the papoo · papoo | High7.5 | — | 2.0% | Jul 12, 2006 |
30Monitor | CVE-2005-4478Proof of concept | Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuipapoo · papoo · CWE-89 | High7.5 | — | 1.3% | Dec 22, 2005 |
30Monitor | CVE-2008-3724No exploit | SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl papoo · papoo · CWE-89 | High7.5 | — | 1.3% | Aug 20, 2008 |
30Monitor | CVE-2007-3453No exploit | SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid papoo · papoo | High7.5 | — | 1.3% | Jun 26, 2007 |
30Monitor | CVE-2007-2320Proof of concept | SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuipapoo · papoo | High7.5 | — | 1.2% | Apr 26, 2007 |
28Monitor | CVE-2007-3494No exploit | Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote papoo · papoo | Medium6.8 | — | 2.1% | Jun 29, 2007 |
25Monitor | CVE-2006-1766No exploit | Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands viapapoo · papoo | Medium6.4 | — | 1.0% | Apr 13, 2006 |
21Monitor | CVE-2009-0735Proof of concept | Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc ipapoo · papoo · CWE-22 | Medium5.1 | — | 2.2% | Feb 25, 2009 |
18Monitor | CVE-2014-9522Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web scrippapoo · cms papoo light · CWE-79 | Medium4.3 | — | 3.5% | Jan 5, 2015 |
17Monitor | CVE-2006-0569No exploit | Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web scriptpapoo · papoo | Medium4.3 | — | 1.2% | Feb 7, 2006 |
15Monitor | CVE-2007-3269No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web scriptpapoo · papoo cms light | Low3.5 | — | 1.8% | Jun 19, 2007 |
11Monitor | CVE-2006-3571Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrapapoo · papoo · CWE-79 | Low2.6 | — | 2.4% | Jul 12, 2006 |
11Monitor | CVE-2006-1918Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menpapoo · papoo · CWE-79 | Low2.6 | — | 1.7% | Apr 20, 2006 |
- CVE-2021-2905435Monitor
Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface.
HighCVSS 8.8No exploitEPSS 1%papoo · papooApr 13, 2021
- CVE-2006-357231Monitor
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 2%papoo · papooJul 12, 2006
- CVE-2005-447830Monitor
Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menui
HighCVSS 7.5Proof of conceptEPSS 1%papoo · papooDec 22, 2005
- CVE-2008-372430Monitor
SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl
HighCVSS 7.5No exploitEPSS 1%papoo · papooAug 20, 2008
- CVE-2007-345330Monitor
SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid
HighCVSS 7.5No exploitEPSS 1%papoo · papooJun 26, 2007
- CVE-2007-232030Monitor
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menui
HighCVSS 7.5Proof of conceptEPSS 1%papoo · papooApr 26, 2007
- CVE-2007-349428Monitor
Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote
MediumCVSS 6.8No exploitEPSS 2%papoo · papooJun 29, 2007
- CVE-2006-176625Monitor
Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via
MediumCVSS 6.4No exploitEPSS 1%papoo · papooApr 13, 2006
- CVE-2009-073521Monitor
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc i
MediumCVSS 5.1Proof of conceptEPSS 2%papoo · papooFeb 25, 2009
- CVE-2014-952218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web scrip
MediumCVSS 4.3Proof of conceptEPSS 4%papoo · cms papoo lightJan 5, 2015
- CVE-2006-056917Monitor
Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%papoo · papooFeb 7, 2006
- CVE-2007-326915Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script
LowCVSS 3.5No exploitEPSS 2%papoo · papoo cms lightJun 19, 2007
- CVE-2006-357111Monitor
Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitra
LowCVSS 2.6Proof of conceptEPSS 2%papoo · papooJul 12, 2006
- CVE-2006-191811Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the men
LowCVSS 2.6Proof of conceptEPSS 2%papoo · papooApr 20, 2006