Skip to content
Noroxi

Stash records

3 published records for vendor stash.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    All records

    3 records
    • CVE-2008-4081
      31Monitor

      admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.

      HighCVSS 7.5Proof of conceptEPSS 3%

      stash · stashSep 15, 2008

    • CVE-2008-4590
      30Monitor

      Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username paramete

      HighCVSS 7.5Proof of conceptEPSS 1%

      stash · stashOct 16, 2008

    • CVE-2008-4080
      28Monitor

      SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via

      MediumCVSS 6.8Proof of conceptEPSS 3%

      stash · stashSep 15, 2008