Записи exv2
11 опубликованных записей вендора exv2.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2006-7079Proof of concept | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program vexv2 · content management system · CWE-22 | Критическая9,8 | — | 12,9 % | 2 мар. 2007 г. |
36Наблюдать | CVE-2007-1966Эксплойта нет | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookiexv2 · content management system · CWE-287 | Критическая9,1 | — | 1,2 % | 11 апр. 2007 г. |
30Наблюдать | CVE-2008-1349Proof of concept | SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers toexv2 · bamagalerie · CWE-89 | Высокая7,5 | — | 1,2 % | 17 мар. 2008 г. |
30Наблюдать | CVE-2006-5030Proof of concept | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitraryexv2 · content management system | Высокая7,5 | — | 1,1 % | 27 сент. 2006 г. |
27Наблюдать | CVE-2008-1404Proof of concept | SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrexv2 · exv2 · CWE-89 | Средняя6,8 | — | 0,9 % | 20 мар. 2008 г. |
27Наблюдать | CVE-2008-1407Proof of concept | SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via texv2 · exv2 · CWE-89 | Средняя6,8 | — | 0,9 % | 20 мар. 2008 г. |
27Наблюдать | CVE-2008-1406Proof of concept | SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commaexv2 · exv2 · CWE-89 | Средняя6,8 | — | 0,9 % | 20 мар. 2008 г. |
18Наблюдать | CVE-2006-7080Proof of concept | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary filesexv2 · content management system | Средняя4,3 | — | 4,7 % | 2 мар. 2007 г. |
17Наблюдать | CVE-2010-4155Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (exv2 · exv2 · CWE-79 | Средняя4,3 | — | 1,1 % | 3 нояб. 2010 г. |
17Наблюдать | CVE-2007-4365Эксплойта нет | Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a exv2 · content management system | Средняя4,3 | — | 1,1 % | 15 авг. 2007 г. |
17Наблюдать | CVE-2007-1965Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script orexv2 · content management system | Средняя4,3 | — | 1,0 % | 11 апр. 2007 г. |
- CVE-2006-707943В плане
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program v
КритическаяCVSS 9,8Proof of conceptEPSS 13 %exv2 · content management system2 мар. 2007 г.
- CVE-2007-196636Наблюдать
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cooki
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %exv2 · content management system11 апр. 2007 г.
- CVE-2008-134930Наблюдать
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %exv2 · bamagalerie17 мар. 2008 г.
- CVE-2006-503030Наблюдать
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %exv2 · content management system27 сент. 2006 г.
- CVE-2008-140427Наблюдать
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitr
СредняяCVSS 6,8Proof of conceptEPSS 1 %exv2 · exv220 мар. 2008 г.
- CVE-2008-140727Наблюдать
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via t
СредняяCVSS 6,8Proof of conceptEPSS 1 %exv2 · exv220 мар. 2008 г.
- CVE-2008-140627Наблюдать
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL comma
СредняяCVSS 6,8Proof of conceptEPSS 1 %exv2 · exv220 мар. 2008 г.
- CVE-2006-708018Наблюдать
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files
СредняяCVSS 4,3Proof of conceptEPSS 5 %exv2 · content management system2 мар. 2007 г.
- CVE-2010-415517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (
СредняяCVSS 4,3Эксплойта нетEPSS 1 %exv2 · exv23 нояб. 2010 г.
- CVE-2007-436517Наблюдать
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %exv2 · content management system15 авг. 2007 г.
- CVE-2007-196517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 1 %exv2 · content management system11 апр. 2007 г.