Skip to content
Noroxi

uapplication records

13 published records for vendor uapplication.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    13 records
    • CVE-2005-1427
      31Monitor

      Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information vi

      HighCVSS 7.5No exploitEPSS 2%

      uapplication · uphotogalleryMay 3, 2005

    • CVE-2005-1428
      30Monitor

      edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.

      HighCVSS 7.5No exploitEPSS 1%

      uapplication · uphotogalleryMay 3, 2005

    • CVE-2006-6247
      30Monitor

      Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci

      HighCVSS 7.5Proof of conceptEPSS 1%

      uapplication · uphotogalleryDec 4, 2006

    • CVE-2007-0799
      30Monitor

      SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified v

      HighCVSS 7.5No exploitEPSS 1%

      uapplication · ublogFeb 6, 2007

    • CVE-2006-2246
      23Monitor

      Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text

      MediumCVSS 5.8No exploitEPSS 1%

      uapplication · ublogMay 9, 2006

    • CVE-2005-1425
      20Monitor

      Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers

      MediumCVSS 5.0No exploitEPSS 2%

      uapplication · uguestbookMay 3, 2005

    • CVE-2005-1426
      20Monitor

      Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to

      MediumCVSS 5.0No exploitEPSS 2%

      uapplication · ublogMay 3, 2005

    • CVE-2005-0938
      20Monitor

      Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwor

      MediumCVSS 5.0No exploitEPSS 1%

      uapplication · ublog reloadMay 2, 2005

    • CVE-2005-2010
      18Monitor

      Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HT

      MediumCVSS 4.3Proof of conceptEPSS 4%

      uapplication · ublog reloadJun 20, 2005

    • CVE-2007-0798
      18Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via

      MediumCVSS 4.3No exploitEPSS 2%

      uapplication · ublog reloadFeb 6, 2007

    • CVE-2005-0925
      18Monitor

      Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web scr

      MediumCVSS 4.3Proof of conceptEPSS 2%

      uapplication · ublog reloadMay 2, 2005

    • CVE-2006-3023
      18Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers t

      MediumCVSS 4.3No exploitEPSS 2%

      uapplication · uphotogalleryJun 15, 2006

    • CVE-2007-0815
      17Monitor

      Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators

      MediumCVSS 4.3No exploitEPSS 1%

      uapplication · uphotogalleryFeb 7, 2007