turnkeyforms records
12 published records for vendor turnkeyforms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-6939Proof of concept | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adturnkeyforms · web hosting directory · CWE-287 | High7.5 | — | 3.1% | Aug 12, 2009 |
31Monitor | CVE-2008-6940Proof of concept | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attturnkeyforms · web hosting directory · CWE-264 | High7.5 | — | 2.8% | Aug 12, 2009 |
31Monitor | CVE-2008-6723Proof of concept | TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoturnkeyforms · entertainment portal · CWE-287 | High7.5 | — | 2.6% | Apr 14, 2009 |
31Monitor | CVE-2008-6302Proof of concept | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_turnkeyforms · local classifieds · CWE-264 | High7.5 | — | 2.6% | Feb 26, 2009 |
31Monitor | CVE-2008-6963Proof of concept | admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct rturnkeyforms · text link sales · CWE-264 | High7.5 | — | 2.5% | Aug 13, 2009 |
30Monitor | CVE-2008-6941Proof of concept | SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQturnkeyforms · web hosting directory · CWE-89 | High7.5 | — | 1.1% | Aug 12, 2009 |
30Monitor | CVE-2008-5486Proof of concept | SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the iturnkeyforms · text link sales · CWE-89 | High7.5 | — | 1.0% | Dec 12, 2008 |
30Monitor | CVE-2008-6350Proof of concept | SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via turnkeyforms · local classifieds · CWE-89 | High7.5 | — | 1.0% | Mar 2, 2009 |
30Monitor | CVE-2008-6349Proof of concept | SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary turnkeyforms · business survey pro · CWE-89 | High7.5 | — | 1.0% | Mar 2, 2009 |
17Monitor | CVE-2008-5487Proof of concept | Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web scriptturnkeyforms · text link sales · CWE-79 | Medium4.3 | — | 1.6% | Dec 12, 2008 |
17Monitor | CVE-2008-6351Proof of concept | Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web sturnkeyforms · local classifieds · CWE-79 | Medium4.3 | — | 1.5% | Mar 2, 2009 |
17Monitor | CVE-2009-4858Proof of concept | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web scriptturnkeyforms · yahoo-answers-clone · CWE-79 | Medium4.3 | — | 1.3% | May 11, 2010 |
- CVE-2008-693931Monitor
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the ad
HighCVSS 7.5Proof of conceptEPSS 3%turnkeyforms · web hosting directoryAug 12, 2009
- CVE-2008-694031Monitor
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote att
HighCVSS 7.5Proof of conceptEPSS 3%turnkeyforms · web hosting directoryAug 12, 2009
- CVE-2008-672331Monitor
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLo
HighCVSS 7.5Proof of conceptEPSS 3%turnkeyforms · entertainment portalApr 14, 2009
- CVE-2008-630231Monitor
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_
HighCVSS 7.5Proof of conceptEPSS 3%turnkeyforms · local classifiedsFeb 26, 2009
- CVE-2008-696331Monitor
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct r
HighCVSS 7.5Proof of conceptEPSS 2%turnkeyforms · text link salesAug 13, 2009
- CVE-2008-694130Monitor
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQ
HighCVSS 7.5Proof of conceptEPSS 1%turnkeyforms · web hosting directoryAug 12, 2009
- CVE-2008-548630Monitor
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the i
HighCVSS 7.5Proof of conceptEPSS 1%turnkeyforms · text link salesDec 12, 2008
- CVE-2008-635030Monitor
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%turnkeyforms · local classifiedsMar 2, 2009
- CVE-2008-634930Monitor
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 1%turnkeyforms · business survey proMar 2, 2009
- CVE-2008-548717Monitor
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%turnkeyforms · text link salesDec 12, 2008
- CVE-2008-635117Monitor
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web s
MediumCVSS 4.3Proof of conceptEPSS 1%turnkeyforms · local classifiedsMar 2, 2009
- CVE-2009-485817Monitor
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 1%turnkeyforms · yahoo-answers-cloneMay 11, 2010