Записи activeweb
4 опубликованных записей вендора activeweb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
27Наблюдать | CVE-2007-3013Proof of concept | SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbactiveweb · contentserver | Средняя6,5 | — | 2,9 % | 15 июл. 2007 г. |
18Наблюдать | CVE-2007-3017Proof of concept | The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysactiveweb · contentserver | Средняя4,0 | — | 5,1 % | 16 июл. 2007 г. |
18Наблюдать | CVE-2007-3014Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary weactiveweb · contentserver | Средняя4,3 | — | 4,5 % | 15 июл. 2007 г. |
16Наблюдать | CVE-2007-3018Эксплойта нет | activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows tactiveweb · contentserver | Средняя4,0 | — | 1,0 % | 16 июл. 2007 г. |
- CVE-2007-301327Наблюдать
SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arb
СредняяCVSS 6,5Proof of conceptEPSS 3 %activeweb · contentserver15 июл. 2007 г.
- CVE-2007-301718Наблюдать
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wys
СредняяCVSS 4,0Proof of conceptEPSS 5 %activeweb · contentserver16 июл. 2007 г.
- CVE-2007-301418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary we
СредняяCVSS 4,3Proof of conceptEPSS 4 %activeweb · contentserver15 июл. 2007 г.
- CVE-2007-301816Наблюдать
activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows t
СредняяCVSS 4,0Эксплойта нетEPSS 1 %activeweb · contentserver16 июл. 2007 г.