Записи ej3
7 опубликованных записей вендора ej3.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2006-3536Эксплойта нет | Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbiej3 · topo | Высокая7,5 | — | 1,5 % | 12 июл. 2006 г. |
21Наблюдать | CVE-2003-1409Proof of concept | TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) ej3 · topo · CWE-200 | Средняя5,0 | — | 2,5 % | 31 дек. 2003 г. |
20Наблюдать | CVE-2005-1716Эксплойта нет | TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remoteej3 · topo | Средняя5,0 | — | 1,5 % | 24 мая 2005 г. |
20Наблюдать | CVE-2006-3833Эксплойта нет | index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries ej3 · topo | Средняя5,0 | — | 1,4 % | 25 июл. 2006 г. |
20Наблюдать | CVE-2006-3834Эксплойта нет | EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry pej3 · topo | Средняя5,0 | — | 1,0 % | 25 июл. 2006 г. |
18Наблюдать | CVE-2006-0984Proof of concept | Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTMej3 · topo | Средняя4,3 | — | 2,0 % | 3 мар. 2006 г. |
18Наблюдать | CVE-2005-1715Proof of concept | Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML ej3 · topo | Средняя4,3 | — | 2,0 % | 24 мая 2005 г. |
- CVE-2006-353630Наблюдать
Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ej3 · topo12 июл. 2006 г.
- CVE-2003-140921Наблюдать
TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2)
СредняяCVSS 5,0Proof of conceptEPSS 3 %ej3 · topo31 дек. 2003 г.
- CVE-2005-171620Наблюдать
TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote
СредняяCVSS 5,0Эксплойта нетEPSS 2 %ej3 · topo24 мая 2005 г.
- CVE-2006-383320Наблюдать
index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries
СредняяCVSS 5,0Эксплойта нетEPSS 1 %ej3 · topo25 июл. 2006 г.
- CVE-2006-383420Наблюдать
EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry p
СредняяCVSS 5,0Эксплойта нетEPSS 1 %ej3 · topo25 июл. 2006 г.
- CVE-2006-098418Наблюдать
Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Proof of conceptEPSS 2 %ej3 · topo3 мар. 2006 г.
- CVE-2005-171518Наблюдать
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 2 %ej3 · topo24 мая 2005 г.