Записи exponent
16 опубликованных записей вендора exponent.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2006-1604Эксплойта нет | Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not exponent · exponent cms | Критическая10,0 | — | 1,7 % | 4 апр. 2006 г. |
40В плане | CVE-2005-3764Эксплойта нет | The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded filesexponent · exponent | Критическая10,0 | — | 1,4 % | 22 нояб. 2005 г. |
31Наблюдать | CVE-2006-1605Эксплойта нет | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknoexponent · exponent cms | Высокая7,5 | — | 2,8 % | 4 апр. 2006 г. |
31Наблюдать | CVE-2005-3765Эксплойта нет | Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers toexponent · exponent | Высокая7,5 | — | 2,7 % | 22 нояб. 2005 г. |
30Наблюдать | CVE-2005-3762Эксплойта нет | SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers toexponent · exponent | Высокая7,5 | — | 1,5 % | 22 нояб. 2005 г. |
30Наблюдать | CVE-2006-1607Эксплойта нет | Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.exponent · exponent cms | Высокая7,5 | — | 1,5 % | 4 апр. 2006 г. |
27Наблюдать | CVE-2006-4963Proof of concept | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via exponent · exponent cms | Средняя6,4 | — | 7,0 % | 23 сент. 2006 г. |
21Наблюдать | CVE-2007-2252Proof of concept | Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive infexponent · exponent cms | Средняя5,0 | — | 2,8 % | 25 апр. 2007 г. |
21Наблюдать | CVE-2005-0310Эксплойта нет | Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.infoexponent · exponent | Средняя5,0 | — | 1,7 % | 2 мая 2005 г. |
20Наблюдать | CVE-2005-3763Эксплойта нет | Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackersexponent · exponent | Средняя5,0 | — | 1,4 % | 22 нояб. 2005 г. |
20Наблюдать | CVE-2005-3767Эксплойта нет | Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and eexponent · exponent | Средняя5,0 | — | 1,4 % | 22 нояб. 2005 г. |
20Наблюдать | CVE-2007-2253Эксплойта нет | Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrolexponent · exponent cms · CWE-200 | Средняя5,0 | — | 1,3 % | 25 апр. 2007 г. |
20Наблюдать | CVE-2006-1606Эксплойта нет | Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.exponent · exponent cms | Средняя5,0 | — | 1,2 % | 4 апр. 2006 г. |
20Наблюдать | CVE-2005-3766Эксплойта нет | Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though exponent · exponent | Средняя5,0 | — | 1,2 % | 22 нояб. 2005 г. |
17Наблюдать | CVE-2005-0309Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrexponent · exponent | Средняя4,3 | — | 1,2 % | 25 янв. 2005 г. |
17Наблюдать | CVE-2005-3761Эксплойта нет | Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script orexponent · exponent | Средняя4,3 | — | 1,2 % | 22 нояб. 2005 г. |
- CVE-2006-160441В плане
Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %exponent · exponent cms4 апр. 2006 г.
- CVE-2005-376440В плане
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.
- CVE-2006-160531Наблюдать
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unkno
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %exponent · exponent cms4 апр. 2006 г.
- CVE-2005-376531Наблюдать
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %exponent · exponent22 нояб. 2005 г.
- CVE-2005-376230Наблюдать
SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.
- CVE-2006-160730Наблюдать
Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %exponent · exponent cms4 апр. 2006 г.
- CVE-2006-496327Наблюдать
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via
СредняяCVSS 6,4Proof of conceptEPSS 7 %exponent · exponent cms23 сент. 2006 г.
- CVE-2007-225221Наблюдать
Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive inf
СредняяCVSS 5,0Proof of conceptEPSS 3 %exponent · exponent cms25 апр. 2007 г.
- CVE-2005-031021Наблюдать
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info
СредняяCVSS 5,0Эксплойта нетEPSS 2 %exponent · exponent2 мая 2005 г.
- CVE-2005-376320Наблюдать
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.
- CVE-2005-376720Наблюдать
Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and e
СредняяCVSS 5,0Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.
- CVE-2007-225320Наблюдать
Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol
СредняяCVSS 5,0Эксплойта нетEPSS 1 %exponent · exponent cms25 апр. 2007 г.
- CVE-2006-160620Наблюдать
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %exponent · exponent cms4 апр. 2006 г.
- CVE-2005-376620Наблюдать
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though
СредняяCVSS 5,0Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.
- CVE-2005-030917Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitr
СредняяCVSS 4,3Эксплойта нетEPSS 1 %exponent · exponent25 янв. 2005 г.
- CVE-2005-376117Наблюдать
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 1 %exponent · exponent22 нояб. 2005 г.