Перейти к содержимому
Noroxi

Записи dcscripts

10 опубликованных записей вендора dcscripts.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

      Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

      CWE

      Все записи

      10 записей
      • CVE-2001-0527
        41В плане

        DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines

        КритическаяCVSS 10,0Proof of conceptEPSS 5 %

        dcscripts · dcforum14 авг. 2001 г.

      • CVE-2001-0436
        31Наблюдать

        dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a

        ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

        dcscripts · dcforum2 июл. 2001 г.

      • CVE-2002-0226
        31Наблюдать

        retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to requ

        ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

        dcscripts · dcforum16 мая 2002 г.

      • CVE-2000-1132
        28Наблюдать

        DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" varia

        СредняяCVSS 6,4Proof of conceptEPSS 9 %

        dcscripts · dcforum9 янв. 2001 г.

      • CVE-2001-0821
        21Наблюдать

        The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read s

        СредняяCVSS 5,0Proof of conceptEPSS 4 %

        dcscripts · dcshop6 дек. 2001 г.

      • CVE-2002-0492
        21Наблюдать

        dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.

        СредняяCVSS 5,0Proof of conceptEPSS 2 %

        dcscripts · dcshop12 авг. 2002 г.

      • CVE-2001-0437
        21Наблюдать

        upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to u

        СредняяCVSS 5,0Эксплойта нетEPSS 2 %

        dcscripts · dcforum2 июл. 2001 г.

      • CVE-2006-2050
        20Наблюдать

        SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        dcscripts · dcforumlite26 апр. 2006 г.

      • CVE-2005-4311
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary

        СредняяCVSS 4,3Proof of conceptEPSS 2 %

        dcscripts · dcforum16 дек. 2005 г.

      • CVE-2006-2049
        17Наблюдать

        Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script

        СредняяCVSS 4,3Эксплойта нетEPSS 1 %

        dcscripts · dcforumlite26 апр. 2006 г.