pilotgroup records
6 published records for vendor pilotgroup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-15969Proof of concept | PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.pilotgroup · allsharevideo · CWE-89 | Critical9.8 | — | 2.1% | Oct 29, 2017 |
30Monitor | CVE-2010-2354Proof of concept | SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the pilotgroup · elms pro · CWE-89 | High7.5 | — | 1.2% | Jun 21, 2010 |
30Monitor | CVE-2008-6117Proof of concept | SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_ipilotgroup · pg job site pro · CWE-89 | High7.5 | — | 1.0% | Feb 11, 2009 |
17Monitor | CVE-2009-3513Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or Hpilotgroup · pg etraining · CWE-79 | Medium4.3 | — | 1.5% | Oct 1, 2009 |
17Monitor | CVE-2010-2355Proof of concept | Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script orpilotgroup · elms pro · CWE-79 | Medium4.3 | — | 1.5% | Jun 21, 2010 |
17Monitor | CVE-2010-2356Proof of concept | Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web scrippilotgroup · elms pro · CWE-79 | Medium4.3 | — | 1.4% | Jun 21, 2010 |
- CVE-2017-1596940Plan
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
CriticalCVSS 9.8Proof of conceptEPSS 2%pilotgroup · allsharevideoOct 29, 2017
- CVE-2010-235430Monitor
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%pilotgroup · elms proJun 21, 2010
- CVE-2008-611730Monitor
SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_i
HighCVSS 7.5Proof of conceptEPSS 1%pilotgroup · pg job site proFeb 11, 2009
- CVE-2009-351317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or H
MediumCVSS 4.3Proof of conceptEPSS 2%pilotgroup · pg etrainingOct 1, 2009
- CVE-2010-235517Monitor
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or
MediumCVSS 4.3Proof of conceptEPSS 1%pilotgroup · elms proJun 21, 2010
- CVE-2010-235617Monitor
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web scrip
MediumCVSS 4.3Proof of conceptEPSS 1%pilotgroup · elms proJun 21, 2010