scriptsez records
23 published records for vendor scriptsez.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2007-0518Proof of concept | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allowscriptsez · smart php subscriber | High7.5 | — | 2.5% | Jan 25, 2007 |
31Monitor | CVE-2009-4683Proof of concept | Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via direscriptsez · good\/bad vote · CWE-22 | High7.5 | — | 2.4% | Mar 10, 2010 |
30Monitor | CVE-2007-0517No exploit | Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackescriptsez · random php quote | High7.5 | — | 1.5% | Jan 25, 2007 |
30Monitor | CVE-2012-0983Proof of concept | SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a viscriptsez · ez album · CWE-89 | High7.5 | — | 1.0% | Feb 2, 2012 |
27Monitor | CVE-2009-4385Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the auscriptsez · ez poll hoster · CWE-352 | Medium6.8 | — | 1.0% | Dec 22, 2009 |
27Monitor | CVE-2009-4826Proof of concept | Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack thscriptsez · mini hosting panel · CWE-352 | Medium6.8 | — | 0.9% | Apr 27, 2010 |
21Monitor | CVE-2008-6089Proof of concept | Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a ..scriptsez · easy image downloader · CWE-22 | Medium5.0 | — | 3.1% | Feb 6, 2009 |
21Monitor | CVE-2008-6112Proof of concept | Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a ..scriptsez · ez ringtone manager · CWE-22 | Medium5.0 | — | 3.0% | Feb 11, 2009 |
21Monitor | CVE-2008-5218Proof of concept | ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cscriptsez · freeze greetings · CWE-264 | Medium5.0 | — | 2.7% | Nov 25, 2008 |
18Monitor | CVE-2009-3601Proof of concept | Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script scriptsez · ultimate poll · CWE-79 | Medium4.3 | — | 3.0% | Oct 8, 2009 |
18Monitor | CVE-2008-2116Proof of concept | Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local scriptsez · power editor · CWE-22 | Medium4.4 | — | 2.5% | May 8, 2008 |
18Monitor | CVE-2008-6090Proof of concept | Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via ascriptsez · mini hosting panel · CWE-22 | Medium4.3 | — | 2.3% | Feb 6, 2009 |
18Monitor | CVE-2006-3004No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML viascriptsez · ez ringtone manager | Medium4.3 | — | 2.1% | Jun 12, 2006 |
17Monitor | CVE-2009-2551Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web scriptscriptsez · easy image downloader · CWE-79 | Medium4.3 | — | 1.5% | Jul 20, 2009 |
17Monitor | CVE-2009-4366Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTMscriptsez · ez blog · CWE-79 | Medium4.3 | — | 1.5% | Dec 21, 2009 |
17Monitor | CVE-2008-2115Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrascriptsez · power editor · CWE-79 | Medium4.3 | — | 1.5% | May 8, 2008 |
17Monitor | CVE-2009-4384Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web scrscriptsez · ez poll hoster · CWE-79 | Medium4.3 | — | 1.5% | Dec 22, 2009 |
17Monitor | CVE-2009-4364Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML viscriptsez · ez blog · CWE-79 | Medium4.3 | — | 1.5% | Dec 21, 2009 |
17Monitor | CVE-2009-4682Proof of concept | Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via thescriptsez · good\/bad vote · CWE-79 | Medium4.3 | — | 1.4% | Mar 10, 2010 |
17Monitor | CVE-2006-2232No exploit | Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTMLscriptsez · cute guestbook | Medium4.3 | — | 1.2% | May 5, 2006 |
17Monitor | CVE-2009-4317No exploit | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML viscriptsez · ez cart · CWE-79 | Medium4.3 | — | 1.1% | Dec 14, 2009 |
17Monitor | CVE-2009-0762No exploit | Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the scriptsez · ez php comment · CWE-79 | Medium4.3 | — | 1.0% | Mar 6, 2009 |
17Monitor | CVE-2009-4365Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authenscriptsez · ez blog · CWE-352 | Medium4.3 | — | 0.9% | Dec 21, 2009 |
- CVE-2007-051831Monitor
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allow
HighCVSS 7.5Proof of conceptEPSS 2%scriptsez · smart php subscriberJan 25, 2007
- CVE-2009-468331Monitor
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via dire
HighCVSS 7.5Proof of conceptEPSS 2%scriptsez · good\/bad voteMar 10, 2010
- CVE-2007-051730Monitor
Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attacke
HighCVSS 7.5No exploitEPSS 1%scriptsez · random php quoteJan 25, 2007
- CVE-2012-098330Monitor
SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a vi
HighCVSS 7.5Proof of conceptEPSS 1%scriptsez · ez albumFeb 2, 2012
- CVE-2009-438527Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the au
MediumCVSS 6.8Proof of conceptEPSS 1%scriptsez · ez poll hosterDec 22, 2009
- CVE-2009-482627Monitor
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack th
MediumCVSS 6.8Proof of conceptEPSS 1%scriptsez · mini hosting panelApr 27, 2010
- CVE-2008-608921Monitor
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 3%scriptsez · easy image downloaderFeb 6, 2009
- CVE-2008-611221Monitor
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 3%scriptsez · ez ringtone managerFeb 11, 2009
- CVE-2008-521821Monitor
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain c
MediumCVSS 5.0Proof of conceptEPSS 3%scriptsez · freeze greetingsNov 25, 2008
- CVE-2009-360118Monitor
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 3%scriptsez · ultimate pollOct 8, 2009
- CVE-2008-211618Monitor
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local
MediumCVSS 4.4Proof of conceptEPSS 3%scriptsez · power editorMay 8, 2008
- CVE-2008-609018Monitor
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a
MediumCVSS 4.3Proof of conceptEPSS 2%scriptsez · mini hosting panelFeb 6, 2009
- CVE-2006-300418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 2%scriptsez · ez ringtone managerJun 12, 2006
- CVE-2009-255117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%scriptsez · easy image downloaderJul 20, 2009
- CVE-2009-436617Monitor
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3Proof of conceptEPSS 2%scriptsez · ez blogDec 21, 2009
- CVE-2008-211517Monitor
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitra
MediumCVSS 4.3Proof of conceptEPSS 1%scriptsez · power editorMay 8, 2008
- CVE-2009-438417Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web scr
MediumCVSS 4.3Proof of conceptEPSS 1%scriptsez · ez poll hosterDec 22, 2009
- CVE-2009-436417Monitor
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3Proof of conceptEPSS 1%scriptsez · ez blogDec 21, 2009
- CVE-2009-468217Monitor
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 1%scriptsez · good\/bad voteMar 10, 2010
- CVE-2006-223217Monitor
Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%scriptsez · cute guestbookMay 5, 2006
- CVE-2009-431717Monitor
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 1%scriptsez · ez cartDec 14, 2009
- CVE-2009-076217Monitor
Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3No exploitEPSS 1%scriptsez · ez php commentMar 6, 2009
- CVE-2009-436517Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authen
MediumCVSS 4.3Proof of conceptEPSS 1%scriptsez · ez blogDec 21, 2009