Записи dcscripts
10 опубликованных записей вендора dcscripts.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2001-0527Proof of concept | DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlinesdcscripts · dcforum | Критическая10,0 | — | 4,5 % | 14 авг. 2001 г. |
31Наблюдать | CVE-2001-0436Эксплойта нет | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a dcscripts · dcforum | Высокая7,5 | — | 2,4 % | 2 июл. 2001 г. |
31Наблюдать | CVE-2002-0226Эксплойта нет | retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to requdcscripts · dcforum | Высокая7,5 | — | 1,7 % | 16 мая 2002 г. |
28Наблюдать | CVE-2000-1132Proof of concept | DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variadcscripts · dcforum | Средняя6,4 | — | 9,3 % | 9 янв. 2001 г. |
21Наблюдать | CVE-2001-0821Proof of concept | The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sdcscripts · dcshop | Средняя5,0 | — | 3,9 % | 6 дек. 2001 г. |
21Наблюдать | CVE-2002-0492Proof of concept | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.dcscripts · dcshop | Средняя5,0 | — | 2,0 % | 12 авг. 2002 г. |
21Наблюдать | CVE-2001-0437Эксплойта нет | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to udcscripts · dcforum | Средняя5,0 | — | 1,7 % | 2 июл. 2001 г. |
20Наблюдать | CVE-2006-2050Эксплойта нет | SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the azdcscripts · dcforumlite | Средняя5,0 | — | 1,3 % | 26 апр. 2006 г. |
18Наблюдать | CVE-2005-4311Proof of concept | Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrarydcscripts · dcforum | Средняя4,3 | — | 1,7 % | 16 дек. 2005 г. |
17Наблюдать | CVE-2006-2049Эксплойта нет | Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script dcscripts · dcforumlite | Средняя4,3 | — | 1,4 % | 26 апр. 2006 г. |
- CVE-2001-052741В плане
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines
КритическаяCVSS 10,0Proof of conceptEPSS 5 %dcscripts · dcforum14 авг. 2001 г.
- CVE-2001-043631Наблюдать
dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dcscripts · dcforum2 июл. 2001 г.
- CVE-2002-022631Наблюдать
retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to requ
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dcscripts · dcforum16 мая 2002 г.
- CVE-2000-113228Наблюдать
DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" varia
СредняяCVSS 6,4Proof of conceptEPSS 9 %dcscripts · dcforum9 янв. 2001 г.
- CVE-2001-082121Наблюдать
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read s
СредняяCVSS 5,0Proof of conceptEPSS 4 %dcscripts · dcshop6 дек. 2001 г.
- CVE-2002-049221Наблюдать
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
СредняяCVSS 5,0Proof of conceptEPSS 2 %dcscripts · dcshop12 авг. 2002 г.
- CVE-2001-043721Наблюдать
upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to u
СредняяCVSS 5,0Эксплойта нетEPSS 2 %dcscripts · dcforum2 июл. 2001 г.
- CVE-2006-205020Наблюдать
SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az
СредняяCVSS 5,0Эксплойта нетEPSS 1 %dcscripts · dcforumlite26 апр. 2006 г.
- CVE-2005-431118Наблюдать
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary
СредняяCVSS 4,3Proof of conceptEPSS 2 %dcscripts · dcforum16 дек. 2005 г.
- CVE-2006-204917Наблюдать
Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %dcscripts · dcforumlite26 апр. 2006 г.