Записи ajsquare
16 опубликованных записей вендора ajsquare.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-287 Improper Authentication4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-7041Proof of concept | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.ajsquare · aj classifieds · CWE-287 | Высокая7,5 | — | 2,8 % | 24 авг. 2009 г. |
31Наблюдать | CVE-2008-7051Proof of concept | AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) useajsquare · aj article · CWE-287 | Высокая7,5 | — | 2,5 % | 24 авг. 2009 г. |
30Наблюдать | CVE-2008-7044Proof of concept | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers ajsquare · free polling script · CWE-89 | Высокая7,5 | — | 1,0 % | 24 авг. 2009 г. |
30Наблюдать | CVE-2009-2779Proof of concept | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in ajsquare · aj matrix dna · CWE-89 | Высокая7,5 | — | 1,0 % | 17 авг. 2009 г. |
30Наблюдать | CVE-2009-3203Proof of concept | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parajsquare · aj auction pro-oopd · CWE-89 | Высокая7,5 | — | 1,0 % | 16 сент. 2009 г. |
30Наблюдать | CVE-2010-1876Proof of concept | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatidajsquare · aj shopping cart · CWE-89 | Высокая7,5 | — | 1,0 % | 12 мая 2010 г. |
30Наблюдать | CVE-2010-2915Proof of concept | SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id pajsquare · aj hyip · CWE-89 | Высокая7,5 | — | 1,0 % | 30 июл. 2010 г. |
30Наблюдать | CVE-2008-6721Proof of concept | SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName pajsquare · aj article · CWE-89 | Высокая7,5 | — | 1,0 % | 14 апр. 2009 г. |
30Наблюдать | CVE-2010-2916Proof of concept | SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id pajsquare · aj hyip · CWE-89 | Высокая7,5 | — | 1,0 % | 30 июл. 2010 г. |
26Наблюдать | CVE-2008-7045Proof of concept | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct rajsquare · free polling script · CWE-287 | Средняя6,4 | — | 2,6 % | 24 авг. 2009 г. |
26Наблюдать | CVE-2008-7046Proof of concept | AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/iajsquare · free polling script · CWE-287 | Средняя6,4 | — | 2,2 % | 24 авг. 2009 г. |
23Наблюдать | CVE-2015-2184Proof of concept | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.ajsquare · zeuscart · CWE-200 | Средняя5,0 | — | 8,4 % | 10 мар. 2015 г. |
18Наблюдать | CVE-2015-2182Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ajsquare · zeuscart · CWE-79 | Средняя4,3 | — | 4,5 % | 11 мар. 2015 г. |
18Наблюдать | CVE-2010-5322Proof of concept | Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the ajsquare · zeuscart · CWE-79 | Средняя4,3 | — | 2,6 % | 11 мар. 2015 г. |
18Наблюдать | CVE-2010-2917Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web ajsquare · aj article · CWE-79 | Средняя4,3 | — | 1,7 % | 30 июл. 2010 г. |
17Наблюдать | CVE-2009-4989Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or Hajsquare · aj auction pro-oopd · CWE-79 | Средняя4,3 | — | 1,5 % | 25 авг. 2010 г. |
- CVE-2008-704131Наблюдать
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %ajsquare · aj classifieds24 авг. 2009 г.
- CVE-2008-705131Наблюдать
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) use
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %ajsquare · aj article24 авг. 2009 г.
- CVE-2008-704430Наблюдать
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · free polling script24 авг. 2009 г.
- CVE-2009-277930Наблюдать
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj matrix dna17 авг. 2009 г.
- CVE-2009-320330Наблюдать
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj auction pro-oopd16 сент. 2009 г.
- CVE-2010-187630Наблюдать
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj shopping cart12 мая 2010 г.
- CVE-2010-291530Наблюдать
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj hyip30 июл. 2010 г.
- CVE-2008-672130Наблюдать
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj article14 апр. 2009 г.
- CVE-2010-291630Наблюдать
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %ajsquare · aj hyip30 июл. 2010 г.
- CVE-2008-704526Наблюдать
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct r
СредняяCVSS 6,4Proof of conceptEPSS 3 %ajsquare · free polling script24 авг. 2009 г.
- CVE-2008-704626Наблюдать
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/i
СредняяCVSS 6,4Proof of conceptEPSS 2 %ajsquare · free polling script24 авг. 2009 г.
- CVE-2015-218423Наблюдать
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.
СредняяCVSS 5,0Proof of conceptEPSS 8 %ajsquare · zeuscart10 мар. 2015 г.
- CVE-2015-218218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1)
СредняяCVSS 4,3Proof of conceptEPSS 4 %ajsquare · zeuscart11 мар. 2015 г.
- CVE-2010-532218Наблюдать
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 3 %ajsquare · zeuscart11 мар. 2015 г.
- CVE-2010-291718Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web
СредняяCVSS 4,3Proof of conceptEPSS 2 %ajsquare · aj article30 июл. 2010 г.
- CVE-2009-498917Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or H
СредняяCVSS 4,3Proof of conceptEPSS 1 %ajsquare · aj auction pro-oopd25 авг. 2010 г.