Записи fipsasp
12 опубликованных записей вендора fipsasp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-264 Permissions, Privileges, and Access Controls2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2006-6117Proof of concept | SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the wfipsasp · fipsgallery | Высокая7,5 | — | 1,2 % | 26 нояб. 2006 г. |
30Наблюдать | CVE-2006-6115Proof of concept | SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid pafipsasp · fipscms | Высокая7,5 | — | 1,2 % | 26 нояб. 2006 г. |
30Наблюдать | CVE-2006-6116Proof of concept | SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kfipsasp · fipsforum | Высокая7,5 | — | 1,2 % | 26 нояб. 2006 г. |
30Наблюдать | CVE-2006-6243Proof of concept | Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or fipsasp · fipsshop | Высокая7,5 | — | 1,2 % | 4 дек. 2006 г. |
30Наблюдать | CVE-2008-3417Proof of concept | SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands viafipsasp · fipscms light · CWE-89 | Высокая7,5 | — | 1,0 % | 31 июл. 2008 г. |
30Наблюдать | CVE-2007-2561Proof of concept | SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a dfipsasp · fipscms | Высокая7,5 | — | 1,0 % | 9 мая 2007 г. |
30Наблюдать | CVE-2008-2124Proof of concept | SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parfipsasp · fipscms · CWE-89 | Высокая7,5 | — | 1,0 % | 9 мая 2008 г. |
30Наблюдать | CVE-2008-3722Proof of concept | SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter.fipsasp · fipscms · CWE-89 | Высокая7,5 | — | 1,0 % | 20 авг. 2008 г. |
28Наблюдать | CVE-2006-3022Эксплойта нет | Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script ofipsasp · fipsgallery | Средняя6,8 | — | 2,0 % | 15 июн. 2006 г. |
22Наблюдать | CVE-2009-2022Proof of concept | fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloafipsasp · fipscms light · CWE-264 | Средняя5,0 | — | 5,2 % | 9 июн. 2009 г. |
21Наблюдать | CVE-2010-0765Proof of concept | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a fipsasp · fipsforum · CWE-264 | Средняя5,0 | — | 2,4 % | 2 мар. 2010 г. |
17Наблюдать | CVE-2006-3031Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web sfipsasp · fipscms | Средняя4,3 | — | 1,2 % | 15 июн. 2006 г. |
- CVE-2006-611730Наблюдать
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the w
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipsgallery26 нояб. 2006 г.
- CVE-2006-611530Наблюдать
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipscms26 нояб. 2006 г.
- CVE-2006-611630Наблюдать
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the k
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipsforum26 нояб. 2006 г.
- CVE-2006-624330Наблюдать
Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipsshop4 дек. 2006 г.
- CVE-2008-341730Наблюдать
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipscms light31 июл. 2008 г.
- CVE-2007-256130Наблюдать
SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter, a d
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipscms9 мая 2007 г.
- CVE-2008-212430Наблюдать
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipscms9 мая 2008 г.
- CVE-2008-372230Наблюдать
SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %fipsasp · fipscms20 авг. 2008 г.
- CVE-2006-302228Наблюдать
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script o
СредняяCVSS 6,8Эксплойта нетEPSS 2 %fipsasp · fipsgallery15 июн. 2006 г.
- CVE-2009-202222Наблюдать
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa
СредняяCVSS 5,0Proof of conceptEPSS 5 %fipsasp · fipscms light9 июн. 2009 г.
- CVE-2010-076521Наблюдать
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a
СредняяCVSS 5,0Proof of conceptEPSS 2 %fipsasp · fipsforum2 мар. 2010 г.
- CVE-2006-303117Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web s
СредняяCVSS 4,3Эксплойта нетEPSS 1 %fipsasp · fipscms15 июн. 2006 г.