visualshapers records
15 published records for vendor visualshapers.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2006-4477Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code vvisualshapers · ezcontents | High7.5 | — | 8.1% | Aug 31, 2006 |
31Monitor | CVE-2004-0070Proof of concept | PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the visualshapers · ezcontents | High7.5 | — | 3.0% | Feb 17, 2004 |
31Monitor | CVE-2002-1085No exploit | Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via visualshapers · ezcontents | High7.5 | — | 2.5% | Oct 4, 2002 |
31Monitor | CVE-2004-0132Proof of concept | Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code fromvisualshapers · ezcontents | High7.5 | — | 2.4% | Mar 3, 2004 |
31Monitor | CVE-2002-1086No exploit | Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.visualshapers · ezcontents | High7.5 | — | 1.9% | Oct 4, 2002 |
31Monitor | CVE-2003-1214No exploit | Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictionvisualshapers · ezcontents | High7.5 | — | 1.8% | Feb 11, 2004 |
31Monitor | CVE-2006-4478Proof of concept | SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commanvisualshapers · ezcontents | High7.5 | — | 1.8% | Aug 31, 2006 |
30Monitor | CVE-2008-2135Proof of concept | Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1visualshapers · ezcontents · CWE-89 | High7.5 | — | 1.0% | May 9, 2008 |
26Monitor | CVE-2002-1084No exploit | The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which avisualshapers · ezcontents | Medium6.4 | — | 2.6% | Oct 4, 2002 |
22Monitor | CVE-2008-7054Proof of concept | Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via thevisualshapers · ezcontents · CWE-22 | Medium5.1 | — | 7.0% | Aug 24, 2009 |
21Monitor | CVE-2008-7055Proof of concept | module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitravisualshapers · ezcontents · CWE-22 | Medium5.1 | — | 2.0% | Aug 24, 2009 |
21Monitor | CVE-2002-1083No exploit | Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories usinvisualshapers · ezcontents | Medium5.0 | — | 1.8% | Oct 4, 2002 |
21Monitor | CVE-2002-1087No exploit | The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allovisualshapers · ezcontents | Medium5.0 | — | 1.7% | Oct 4, 2002 |
20Monitor | CVE-2002-1082No exploit | The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local filesvisualshapers · ezcontents | Medium5.0 | — | 1.5% | Oct 4, 2002 |
18Monitor | CVE-2006-4479Proof of concept | Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary webvisualshapers · ezcontents | Medium4.3 | — | 2.1% | Aug 31, 2006 |
- CVE-2006-447732Monitor
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code v
HighCVSS 7.5Proof of conceptEPSS 8%visualshapers · ezcontentsAug 31, 2006
- CVE-2004-007031Monitor
PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the
HighCVSS 7.5Proof of conceptEPSS 3%visualshapers · ezcontentsFeb 17, 2004
- CVE-2002-108531Monitor
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via
HighCVSS 7.5No exploitEPSS 2%visualshapers · ezcontentsOct 4, 2002
- CVE-2004-013231Monitor
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from
HighCVSS 7.5Proof of conceptEPSS 2%visualshapers · ezcontentsMar 3, 2004
- CVE-2002-108631Monitor
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
HighCVSS 7.5No exploitEPSS 2%visualshapers · ezcontentsOct 4, 2002
- CVE-2003-121431Monitor
Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restriction
HighCVSS 7.5No exploitEPSS 2%visualshapers · ezcontentsFeb 11, 2004
- CVE-2006-447831Monitor
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL comman
HighCVSS 7.5Proof of conceptEPSS 2%visualshapers · ezcontentsAug 31, 2006
- CVE-2008-213530Monitor
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1
HighCVSS 7.5Proof of conceptEPSS 1%visualshapers · ezcontentsMay 9, 2008
- CVE-2002-108426Monitor
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which a
MediumCVSS 6.4No exploitEPSS 3%visualshapers · ezcontentsOct 4, 2002
- CVE-2008-705422Monitor
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the
MediumCVSS 5.1Proof of conceptEPSS 7%visualshapers · ezcontentsAug 24, 2009
- CVE-2008-705521Monitor
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitra
MediumCVSS 5.1Proof of conceptEPSS 2%visualshapers · ezcontentsAug 24, 2009
- CVE-2002-108321Monitor
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories usin
MediumCVSS 5.0No exploitEPSS 2%visualshapers · ezcontentsOct 4, 2002
- CVE-2002-108721Monitor
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allo
MediumCVSS 5.0No exploitEPSS 2%visualshapers · ezcontentsOct 4, 2002
- CVE-2002-108220Monitor
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files
MediumCVSS 5.0No exploitEPSS 1%visualshapers · ezcontentsOct 4, 2002
- CVE-2006-447918Monitor
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web
MediumCVSS 4.3Proof of conceptEPSS 2%visualshapers · ezcontentsAug 31, 2006