Перейти к содержимому
Noroxi

Записи auracms

18 опубликованных записей вендора auracms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
11
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2008-0735
    40В плане

    SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands vi

    КритическаяCVSS 10,0Proof of conceptEPSS 2 %

    auracms · auracms12 февр. 2008 г.

  • CVE-2018-16338
    35Наблюдать

    An issue was discovered in AuraCMS 2.3.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    auracms · auracms2 сент. 2018 г.

  • CVE-2007-4905
    32Наблюдать

    Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files vi

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    auracms · auracms17 сент. 2007 г.

  • CVE-2007-4804
    31Наблюдать

    Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1)

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    auracms · auracms11 сент. 2007 г.

  • CVE-2007-4908
    31Наблюдать

    Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local fil

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    auracms · auracms17 сент. 2007 г.

  • CVE-2008-3203
    31Наблюдать

    js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    auracms · auracms17 июл. 2008 г.

  • CVE-2008-0390
    31Наблюдать

    stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via t

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    auracms · auracms22 янв. 2008 г.

  • CVE-2007-4171
    30Наблюдать

    SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbit

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    auracms · modul forum sederhana7 авг. 2007 г.

  • CVE-2008-0811
    30Наблюдать

    Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    auracms · auracms18 февр. 2008 г.

  • CVE-2010-4774
    30Наблюдать

    SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a dif

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    auracms · auracms23 мар. 2011 г.

  • CVE-2007-4886
    28Наблюдать

    Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    auracms · auracms13 сент. 2007 г.

  • CVE-2014-1401
    27Наблюдать

    Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the

    СредняяCVSS 6,5Proof of conceptEPSS 3 %

    auracms · auracms11 февр. 2014 г.

  • CVE-2008-1715
    27Наблюдать

    SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    auracms · auracms9 апр. 2008 г.

  • CVE-2008-1398
    27Наблюдать

    SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-F

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    auracms · auracms20 мар. 2008 г.

  • CVE-2007-6552
    24Наблюдать

    Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files

    СредняяCVSS 6,0Proof of conceptEPSS 2 %

    auracms · auracms27 дек. 2007 г.

  • CVE-2014-3975
    22Наблюдать

    Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in t

    СредняяCVSS 5,0Proof of conceptEPSS 7 %

    auracms · auracms5 июн. 2014 г.

  • CVE-2018-15199
    21Наблюдать

    AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    auracms · auracms7 авг. 2018 г.

  • CVE-2014-3974
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web scrip

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    auracms · auracms5 июн. 2014 г.