phpkobo records
17 published records for vendor phpkobo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 16
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-837 Improper Enforcement of a Single, Unique Action1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-41449No exploit | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.phpkobo · ajaxnewsticker · CWE-918 | Critical9.8 | — | 1.4% | Sep 27, 2023 |
35Monitor | CVE-2023-41450No exploit | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.phpkobo · ajaxnewsticker · CWE-94 | High8.8 | — | 1.2% | Sep 27, 2023 |
35Monitor | CVE-2023-41452No exploit | Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted pphpkobo · ajaxnewsticker · CWE-352 | High8.8 | — | 0.5% | Sep 27, 2023 |
28Monitor | CVE-2010-1057Proof of concept | Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remotephpkobo · adfreely · CWE-22 | Medium6.8 | — | 2.4% | Mar 23, 2010 |
28Monitor | CVE-2010-1058Proof of concept | Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allophpkobo · address book script · CWE-22 | Medium6.8 | — | 2.3% | Mar 23, 2010 |
28Monitor | CVE-2010-1062Proof of concept | Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disaphpkobo · free real estate contact form script · CWE-22 | Medium6.8 | — | 1.9% | Mar 23, 2010 |
28Monitor | CVE-2010-1060Proof of concept | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote atphpkobo · short url · CWE-22 | Medium6.8 | — | 1.9% | Mar 23, 2010 |
27Monitor | CVE-2010-1063No exploit | Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote phpkobo · free real estate contact form script · CWE-22 | Medium6.8 | — | 1.4% | Mar 23, 2010 |
27Monitor | CVE-2010-1061No exploit | Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to includephpkobo · short url · CWE-22 | Medium6.8 | — | 1.4% | Mar 23, 2010 |
27Monitor | CVE-2010-1059No exploit | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allowsphpkobo · address book script · CWE-22 | Medium6.8 | — | 1.3% | Mar 23, 2010 |
24Monitor | CVE-2023-41448No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payloadphpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.7% | Sep 27, 2023 |
24Monitor | CVE-2023-41446No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script phpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.7% | Sep 27, 2023 |
24Monitor | CVE-2023-41447No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payloadphpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.7% | Sep 27, 2023 |
24Monitor | CVE-2023-41451No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payloadphpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.7% | Sep 27, 2023 |
24Monitor | CVE-2023-41453No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payloadphpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.7% | Sep 27, 2023 |
24Monitor | CVE-2023-41445No exploit | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payloadphpkobo · ajaxnewsticker · CWE-79 | Medium6.1 | — | 0.6% | Sep 27, 2023 |
14Monitor | CVE-2023-5313No exploit | phpkobo Ajax Poll Script ajax-poll.php improper enforcement of a single, unique actionphpkobo · ajax poll script · CWE-837 | Low3.7 | — | 0.5% | Sep 30, 2023 |
- CVE-2023-4144939Monitor
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
CriticalCVSS 9.8No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4145035Monitor
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
HighCVSS 8.8No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4145235Monitor
Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted p
HighCVSS 8.8No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2010-105728Monitor
Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote
MediumCVSS 6.8Proof of conceptEPSS 2%phpkobo · adfreelyMar 23, 2010
- CVE-2010-105828Monitor
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allo
MediumCVSS 6.8Proof of conceptEPSS 2%phpkobo · address book scriptMar 23, 2010
- CVE-2010-106228Monitor
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disa
MediumCVSS 6.8Proof of conceptEPSS 2%phpkobo · free real estate contact form scriptMar 23, 2010
- CVE-2010-106028Monitor
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote at
MediumCVSS 6.8Proof of conceptEPSS 2%phpkobo · short urlMar 23, 2010
- CVE-2010-106327Monitor
Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote
MediumCVSS 6.8No exploitEPSS 1%phpkobo · free real estate contact form scriptMar 23, 2010
- CVE-2010-106127Monitor
Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include
MediumCVSS 6.8No exploitEPSS 1%phpkobo · short urlMar 23, 2010
- CVE-2010-105927Monitor
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows
MediumCVSS 6.8No exploitEPSS 1%phpkobo · address book scriptMar 23, 2010
- CVE-2023-4144824Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4144624Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4144724Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4145124Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4145324Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-4144524Monitor
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload
MediumCVSS 6.1No exploitEPSS 1%phpkobo · ajaxnewstickerSep 27, 2023
- CVE-2023-531314Monitor
phpkobo Ajax Poll Script ajax-poll.php improper enforcement of a single, unique action
LowCVSS 3.7No exploitEPSS 0%phpkobo · ajax poll scriptSep 30, 2023