ravenphpscripts records
6 published records for vendor ravenphpscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2009-0677Proof of concept | avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated useravenphpscripts · ravennuke · CWE-94 | Medium6.5 | — | 9.0% | Feb 22, 2009 |
27Monitor | CVE-2009-0673Proof of concept | Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authravenphpscripts · ravennuke · CWE-94 | Medium6.5 | — | 2.7% | Feb 22, 2009 |
26Monitor | CVE-2009-0672Proof of concept | SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to exravenphpscripts · ravennuke · CWE-89 | Medium6.5 | — | 1.3% | Feb 22, 2009 |
25Monitor | CVE-2009-0674Proof of concept | images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to deravenphpscripts · ravennuke · CWE-94 | Medium6.0 | — | 2.3% | Feb 22, 2009 |
21Monitor | CVE-2009-0678Proof of concept | images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does nravenphpscripts · ravennuke · CWE-200 | Medium5.0 | — | 2.8% | Feb 22, 2009 |
17Monitor | CVE-2009-0679No exploit | Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web scriptravenphpscripts · ravennuke · CWE-79 | Medium4.3 | — | 1.1% | Feb 22, 2009 |
- CVE-2009-067729Monitor
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated use
MediumCVSS 6.5Proof of conceptEPSS 9%ravenphpscripts · ravennukeFeb 22, 2009
- CVE-2009-067327Monitor
Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote auth
MediumCVSS 6.5Proof of conceptEPSS 3%ravenphpscripts · ravennukeFeb 22, 2009
- CVE-2009-067226Monitor
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to ex
MediumCVSS 6.5Proof of conceptEPSS 1%ravenphpscripts · ravennukeFeb 22, 2009
- CVE-2009-067425Monitor
images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to de
MediumCVSS 6.0Proof of conceptEPSS 2%ravenphpscripts · ravennukeFeb 22, 2009
- CVE-2009-067821Monitor
images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does n
MediumCVSS 5.0Proof of conceptEPSS 3%ravenphpscripts · ravennukeFeb 22, 2009
- CVE-2009-067917Monitor
Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%ravenphpscripts · ravennukeFeb 22, 2009