prozilla records
15 published records for vendor prozilla.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2004-1120Proof of concept | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and prozilla · prozilla download accelerator | Critical10.0 | — | 14.6% | Jan 10, 2005 |
33Monitor | CVE-2005-0523Proof of concept | Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers iprozilla · prozilla download accelerator | High7.5 | — | 9.9% | May 2, 2005 |
33Monitor | CVE-2005-2961Proof of concept | Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remotprozilla · prozilla download accelerator | High7.5 | — | 8.6% | Oct 5, 2005 |
31Monitor | CVE-2008-1784Proof of concept | Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3)prozilla · topsites · CWE-264 | High7.5 | — | 2.5% | Apr 15, 2008 |
31Monitor | CVE-2008-1863Proof of concept | SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL cprozilla · cheats · CWE-89 | High7.5 | — | 2.1% | Apr 17, 2008 |
30Monitor | CVE-2008-6115Proof of concept | SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id prozilla · hosting index · CWE-89 | High7.5 | — | 1.1% | Feb 11, 2009 |
30Monitor | CVE-2007-3809Proof of concept | Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id prozilla · prozilla directory script | High7.5 | — | 1.0% | Jul 16, 2007 |
30Monitor | CVE-2008-1864Proof of concept | SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the projectprozilla · prozilla freelancers · CWE-89 | High7.5 | — | 1.0% | Apr 17, 2008 |
30Monitor | CVE-2007-4258Proof of concept | SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via thprozilla · prozilla pub site directory · CWE-89 | High7.5 | — | 1.0% | Aug 8, 2007 |
30Monitor | CVE-2008-1788Proof of concept | SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commaprozilla · entertainers · CWE-89 | High7.5 | — | 0.9% | Apr 15, 2008 |
27Monitor | CVE-2007-4362Proof of concept | SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameprozilla · webring | Medium6.8 | — | 1.2% | Aug 15, 2007 |
27Monitor | CVE-2008-2083Proof of concept | SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to executprozilla · hosting index · CWE-89 | Medium6.8 | — | 1.1% | May 5, 2008 |
27Monitor | CVE-2008-1789Proof of concept | SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameterprozilla · forum · CWE-89 | Medium6.8 | — | 0.9% | Apr 15, 2008 |
26Monitor | CVE-2008-1783Proof of concept | Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/Deleprozilla · reviews · CWE-264 | Medium6.4 | — | 2.3% | Apr 15, 2008 |
23Monitor | CVE-2008-1785Proof of concept | delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s pprozilla · top 100 · CWE-20 | Medium5.5 | — | 2.0% | Apr 15, 2008 |
- CVE-2004-112044Plan
Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and
CriticalCVSS 10.0Proof of conceptEPSS 15%prozilla · prozilla download acceleratorJan 10, 2005
- CVE-2005-052333Monitor
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers i
HighCVSS 7.5Proof of conceptEPSS 10%prozilla · prozilla download acceleratorMay 2, 2005
- CVE-2005-296133Monitor
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remot
HighCVSS 7.5Proof of conceptEPSS 9%prozilla · prozilla download acceleratorOct 5, 2005
- CVE-2008-178431Monitor
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3)
HighCVSS 7.5Proof of conceptEPSS 3%prozilla · topsitesApr 15, 2008
- CVE-2008-186331Monitor
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL c
HighCVSS 7.5Proof of conceptEPSS 2%prozilla · cheatsApr 17, 2008
- CVE-2008-611530Monitor
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id
HighCVSS 7.5Proof of conceptEPSS 1%prozilla · hosting indexFeb 11, 2009
- CVE-2007-380930Monitor
Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id
HighCVSS 7.5Proof of conceptEPSS 1%prozilla · prozilla directory scriptJul 16, 2007
- CVE-2008-186430Monitor
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project
HighCVSS 7.5Proof of conceptEPSS 1%prozilla · prozilla freelancersApr 17, 2008
- CVE-2007-425830Monitor
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 1%prozilla · prozilla pub site directoryAug 8, 2007
- CVE-2008-178830Monitor
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 1%prozilla · entertainersApr 15, 2008
- CVE-2007-436227Monitor
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parame
MediumCVSS 6.8Proof of conceptEPSS 1%prozilla · webringAug 15, 2007
- CVE-2008-208327Monitor
SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execut
MediumCVSS 6.8Proof of conceptEPSS 1%prozilla · hosting indexMay 5, 2008
- CVE-2008-178927Monitor
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter
MediumCVSS 6.8Proof of conceptEPSS 1%prozilla · forumApr 15, 2008
- CVE-2008-178326Monitor
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/Dele
MediumCVSS 6.4Proof of conceptEPSS 2%prozilla · reviewsApr 15, 2008
- CVE-2008-178523Monitor
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s p
MediumCVSS 5.5Proof of conceptEPSS 2%prozilla · top 100Apr 15, 2008