Перейти к содержимому
Noroxi

Записи exv2

11 опубликованных записей вендора exv2.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Все записи

    11 записей
    • CVE-2006-7079
      43В плане

      Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program v

      КритическаяCVSS 9,8Proof of conceptEPSS 13 %

      exv2 · content management system2 мар. 2007 г.

    • CVE-2007-1966
      36Наблюдать

      Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cooki

      КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

      exv2 · content management system11 апр. 2007 г.

    • CVE-2008-1349
      30Наблюдать

      SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      exv2 · bamagalerie17 мар. 2008 г.

    • CVE-2006-5030
      30Наблюдать

      SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      exv2 · content management system27 сент. 2006 г.

    • CVE-2008-1404
      27Наблюдать

      SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitr

      СредняяCVSS 6,8Proof of conceptEPSS 1 %

      exv2 · exv220 мар. 2008 г.

    • CVE-2008-1407
      27Наблюдать

      SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via t

      СредняяCVSS 6,8Proof of conceptEPSS 1 %

      exv2 · exv220 мар. 2008 г.

    • CVE-2008-1406
      27Наблюдать

      SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL comma

      СредняяCVSS 6,8Proof of conceptEPSS 1 %

      exv2 · exv220 мар. 2008 г.

    • CVE-2006-7080
      18Наблюдать

      Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files

      СредняяCVSS 4,3Proof of conceptEPSS 5 %

      exv2 · content management system2 мар. 2007 г.

    • CVE-2010-4155
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      exv2 · exv23 нояб. 2010 г.

    • CVE-2007-4365
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      exv2 · content management system15 авг. 2007 г.

    • CVE-2007-1965
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      exv2 · content management system11 апр. 2007 г.