Записи auracms
18 опубликованных записей вендора auracms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2008-0735Proof of concept | SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands viauracms · auracms · CWE-89 | Критическая10,0 | — | 1,5 % | 12 февр. 2008 г. |
35Наблюдать | CVE-2018-16338Эксплойта нет | An issue was discovered in AuraCMS 2.3.auracms · auracms · CWE-352 | Высокая8,8 | — | 0,5 % | 2 сент. 2018 г. |
32Наблюдать | CVE-2007-4905Proof of concept | Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files viauracms · auracms · CWE-20 | Высокая7,5 | — | 7,0 % | 17 сент. 2007 г. |
31Наблюдать | CVE-2007-4804Proof of concept | Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1)auracms · auracms · CWE-89 | Высокая7,5 | — | 3,3 % | 11 сент. 2007 г. |
31Наблюдать | CVE-2007-4908Proof of concept | Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local filauracms · auracms · CWE-22 | Высокая7,5 | — | 2,8 % | 17 сент. 2007 г. |
31Наблюдать | CVE-2008-3203Proof of concept | js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and deleteauracms · auracms · CWE-287 | Высокая7,5 | — | 2,6 % | 17 июл. 2008 г. |
31Наблюдать | CVE-2008-0390Proof of concept | stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via tauracms · auracms · CWE-94 | Высокая7,5 | — | 2,3 % | 22 янв. 2008 г. |
30Наблюдать | CVE-2007-4171Proof of concept | SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitauracms · modul forum sederhana | Высокая7,5 | — | 1,4 % | 7 авг. 2007 г. |
30Наблюдать | CVE-2008-0811Proof of concept | Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter toauracms · auracms · CWE-89 | Высокая7,5 | — | 1,0 % | 18 февр. 2008 г. |
30Наблюдать | CVE-2010-4774Proof of concept | SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a difauracms · auracms · CWE-89 | Высокая7,5 | — | 0,9 % | 23 мар. 2011 г. |
28Наблюдать | CVE-2007-4886Proof of concept | Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a auracms · auracms · CWE-94 | Средняя6,8 | — | 2,1 % | 13 сент. 2007 г. |
27Наблюдать | CVE-2014-1401Proof of concept | Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via theauracms · auracms · CWE-89 | Средняя6,5 | — | 3,0 % | 11 февр. 2014 г. |
27Наблюдать | CVE-2008-1715Proof of concept | SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to auracms · auracms · CWE-89 | Средняя6,8 | — | 0,9 % | 9 апр. 2008 г. |
27Наблюдать | CVE-2008-1398Proof of concept | SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Fauracms · auracms · CWE-89 | Средняя6,8 | — | 0,9 % | 20 мар. 2008 г. |
24Наблюдать | CVE-2007-6552Proof of concept | Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local filesauracms · auracms · CWE-22 | Средняя6,0 | — | 1,6 % | 27 дек. 2007 г. |
22Наблюдать | CVE-2014-3975Proof of concept | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in tauracms · auracms · CWE-22 | Средняя5,0 | — | 6,9 % | 5 июн. 2014 г. |
21Наблюдать | CVE-2018-15199Эксплойта нет | AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.auracms · auracms · CWE-79 | Средняя5,4 | — | 0,6 % | 7 авг. 2018 г. |
18Наблюдать | CVE-2014-3974Proof of concept | Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web scripauracms · auracms · CWE-79 | Средняя4,3 | — | 3,2 % | 5 июн. 2014 г. |
- CVE-2008-073540В плане
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands vi
КритическаяCVSS 10,0Proof of conceptEPSS 2 %auracms · auracms12 февр. 2008 г.
- CVE-2018-1633835Наблюдать
An issue was discovered in AuraCMS 2.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %auracms · auracms2 сент. 2018 г.
- CVE-2007-490532Наблюдать
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files vi
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %auracms · auracms17 сент. 2007 г.
- CVE-2007-480431Наблюдать
Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %auracms · auracms11 сент. 2007 г.
- CVE-2007-490831Наблюдать
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local fil
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %auracms · auracms17 сент. 2007 г.
- CVE-2008-320331Наблюдать
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %auracms · auracms17 июл. 2008 г.
- CVE-2008-039031Наблюдать
stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via t
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %auracms · auracms22 янв. 2008 г.
- CVE-2007-417130Наблюдать
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbit
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %auracms · modul forum sederhana7 авг. 2007 г.
- CVE-2008-081130Наблюдать
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %auracms · auracms18 февр. 2008 г.
- CVE-2010-477430Наблюдать
SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a dif
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %auracms · auracms23 мар. 2011 г.
- CVE-2007-488628Наблюдать
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a
СредняяCVSS 6,8Proof of conceptEPSS 2 %auracms · auracms13 сент. 2007 г.
- CVE-2014-140127Наблюдать
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the
СредняяCVSS 6,5Proof of conceptEPSS 3 %auracms · auracms11 февр. 2014 г.
- CVE-2008-171527Наблюдать
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to
СредняяCVSS 6,8Proof of conceptEPSS 1 %auracms · auracms9 апр. 2008 г.
- CVE-2008-139827Наблюдать
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-F
СредняяCVSS 6,8Proof of conceptEPSS 1 %auracms · auracms20 мар. 2008 г.
- CVE-2007-655224Наблюдать
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files
СредняяCVSS 6,0Proof of conceptEPSS 2 %auracms · auracms27 дек. 2007 г.
- CVE-2014-397522Наблюдать
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in t
СредняяCVSS 5,0Proof of conceptEPSS 7 %auracms · auracms5 июн. 2014 г.
- CVE-2018-1519921Наблюдать
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %auracms · auracms7 авг. 2018 г.
- CVE-2014-397418Наблюдать
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web scrip
СредняяCVSS 4,3Proof of conceptEPSS 3 %auracms · auracms5 июн. 2014 г.