Записи comscripts
19 опубликованных записей вендора comscripts.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2006-4622Proof of concept | PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP codecomscripts · annoncev | Высокая7,5 | — | 3,4 % | 6 сент. 2006 г. |
31Наблюдать | CVE-2010-1114Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP cocomscripts · web server creator web portal · CWE-94 | Высокая7,5 | — | 3,0 % | 25 мар. 2010 г. |
31Наблюдать | CVE-2006-4746Proof of concept | PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrarycomscripts · web server creator | Высокая7,5 | — | 2,6 % | 13 сент. 2006 г. |
31Наблюдать | CVE-2008-6543Proof of concept | Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.phpcomscripts · quick classifieds · CWE-94 | Высокая7,5 | — | 2,5 % | 29 мар. 2009 г. |
31Наблюдать | CVE-2007-0361Proof of concept | PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URLcomscripts · phpmyphorum | Высокая7,5 | — | 2,5 % | 18 янв. 2007 г. |
31Наблюдать | CVE-2006-4678Proof of concept | PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] pcomscripts · news evolution | Высокая7,5 | — | 2,5 % | 11 сент. 2006 г. |
31Наблюдать | CVE-2008-6545Proof of concept | PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to executecomscripts · web server creator web portal · CWE-94 | Высокая7,5 | — | 2,3 % | 29 мар. 2009 г. |
31Наблюдать | CVE-2002-2217Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute comscripts · web server creator | Высокая7,5 | — | 2,1 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2006-3168Эксплойта нет | SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut pcomscripts · cs-forum | Высокая7,5 | — | 1,7 % | 22 июн. 2006 г. |
28Наблюдать | CVE-2006-4754Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML vicomscripts · phprog | Средняя6,8 | — | 2,2 % | 13 сент. 2006 г. |
21Наблюдать | CVE-2006-4753Proof of concept | Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a ..comscripts · phprog | Средняя5,0 | — | 3,5 % | 13 сент. 2006 г. |
21Наблюдать | CVE-2007-1144Эксплойта нет | Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via acomscripts · j-web pics navigator · CWE-22 | Средняя5,0 | — | 3,4 % | 2 мар. 2007 г. |
21Наблюдать | CVE-2007-4937Proof of concept | CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the acomscripts · cs guestbook · CWE-264 | Средняя5,0 | — | 2,6 % | 18 сент. 2007 г. |
21Наблюдать | CVE-2006-3170Эксплойта нет | CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collcomscripts · cs-forum | Средняя5,0 | — | 1,8 % | 22 июн. 2006 г. |
20Наблюдать | CVE-2010-1115Эксплойта нет | Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitcomscripts · web server creator web portal · CWE-22 | Средняя5,0 | — | 1,6 % | 25 мар. 2010 г. |
20Наблюдать | CVE-2006-3171Эксплойта нет | CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in thcomscripts · cs-forum | Средняя5,0 | — | 1,5 % | 22 июн. 2006 г. |
18Наблюдать | CVE-2006-3169Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTcomscripts · cs-forum | Средняя4,3 | — | 1,7 % | 22 июн. 2006 г. |
17Наблюдать | CVE-2008-6655Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via tcomscripts · gedcom to mysl · CWE-79 | Средняя4,3 | — | 1,5 % | 7 апр. 2009 г. |
17Наблюдать | CVE-2010-1113Proof of concept | Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrarcomscripts · web server creator web portal · CWE-79 | Средняя4,3 | — | 1,5 % | 25 мар. 2010 г. |
- CVE-2006-462231Наблюдать
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %comscripts · annoncev6 сент. 2006 г.
- CVE-2010-111431Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP co
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %comscripts · web server creator web portal25 мар. 2010 г.
- CVE-2006-474631Наблюдать
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %comscripts · web server creator13 сент. 2006 г.
- CVE-2008-654331Наблюдать
Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %comscripts · quick classifieds29 мар. 2009 г.
- CVE-2007-036131Наблюдать
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %comscripts · phpmyphorum18 янв. 2007 г.
- CVE-2006-467831Наблюдать
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] p
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %comscripts · news evolution11 сент. 2006 г.
- CVE-2008-654531Наблюдать
PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %comscripts · web server creator web portal29 мар. 2009 г.
- CVE-2002-221731Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %comscripts · web server creator31 дек. 2002 г.
- CVE-2006-316831Наблюдать
SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut p
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %comscripts · cs-forum22 июн. 2006 г.
- CVE-2006-475428Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 6,8Proof of conceptEPSS 2 %comscripts · phprog13 сент. 2006 г.
- CVE-2006-475321Наблюдать
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 3 %comscripts · phprog13 сент. 2006 г.
- CVE-2007-114421Наблюдать
Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a
СредняяCVSS 5,0Эксплойта нетEPSS 3 %comscripts · j-web pics navigator2 мар. 2007 г.
- CVE-2007-493721Наблюдать
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the a
СредняяCVSS 5,0Proof of conceptEPSS 3 %comscripts · cs guestbook18 сент. 2007 г.
- CVE-2006-317021Наблюдать
CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty coll
СредняяCVSS 5,0Эксплойта нетEPSS 2 %comscripts · cs-forum22 июн. 2006 г.
- CVE-2010-111520Наблюдать
Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbit
СредняяCVSS 5,0Эксплойта нетEPSS 2 %comscripts · web server creator web portal25 мар. 2010 г.
- CVE-2006-317120Наблюдать
CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in th
СредняяCVSS 5,0Эксплойта нетEPSS 1 %comscripts · cs-forum22 июн. 2006 г.
- CVE-2006-316918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Эксплойта нетEPSS 2 %comscripts · cs-forum22 июн. 2006 г.
- CVE-2008-665517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 4,3Proof of conceptEPSS 1 %comscripts · gedcom to mysl7 апр. 2009 г.
- CVE-2010-111317Наблюдать
Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrar
СредняяCVSS 4,3Proof of conceptEPSS 1 %comscripts · web server creator web portal25 мар. 2010 г.