Записи bti-tracker
5 опубликованных записей вендора bti-tracker.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2007-5988Эксплойта нет | blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitbti-tracker · bti-tracker · CWE-255 | Высокая7,5 | — | 1,5 % | 14 нояб. 2007 г. |
30Наблюдать | CVE-2007-2854Proof of concept | Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQLbti-tracker · bti-tracker | Высокая7,5 | — | 1,2 % | 24 мая 2007 г. |
27Наблюдать | CVE-2007-5987Эксплойта нет | details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanismsbti-tracker · bti-tracker · CWE-264 | Средняя6,8 | — | 1,3 % | 14 нояб. 2007 г. |
25Наблюдать | CVE-2006-7159Эксплойта нет | Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbibti-tracker · bti-tracker | Средняя6,4 | — | 1,5 % | 7 мар. 2007 г. |
18Наблюдать | CVE-2007-5985Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTMLbti-tracker · bti-tracker · CWE-79 | Средняя4,3 | — | 1,7 % | 14 нояб. 2007 г. |
- CVE-2007-598830Наблюдать
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbit
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bti-tracker · bti-tracker14 нояб. 2007 г.
- CVE-2007-285430Наблюдать
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %bti-tracker · bti-tracker24 мая 2007 г.
- CVE-2007-598727Наблюдать
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms
СредняяCVSS 6,8Эксплойта нетEPSS 1 %bti-tracker · bti-tracker14 нояб. 2007 г.
- CVE-2006-715925Наблюдать
Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbi
СредняяCVSS 6,4Эксплойта нетEPSS 2 %bti-tracker · bti-tracker7 мар. 2007 г.
- CVE-2007-598518Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 2 %bti-tracker · bti-tracker14 нояб. 2007 г.