Записи iatek
11 опубликованных записей вендора iatek.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2002-1659Эксплойта нет | user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.iatek · portalapp | Критическая10,0 | — | 1,8 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2005-1011Proof of concept | SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.iatek · siteenable | Высокая7,5 | — | 2,4 % | 2 мая 2005 г. |
30Наблюдать | CVE-2005-0948Proof of concept | SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameiatek · portalapp | Высокая7,5 | — | 1,3 % | 2 мая 2005 г. |
30Наблюдать | CVE-2008-1430Proof of concept | SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.iatek · aspapp · CWE-89 | Высокая7,5 | — | 0,9 % | 20 мар. 2008 г. |
28Наблюдать | CVE-2005-4482Proof of concept | Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script oriatek · portalapp | Средняя6,8 | — | 2,0 % | 22 дек. 2005 г. |
21Наблюдать | CVE-2004-1786Proof of concept | PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensiiatek · portalapp | Средняя5,0 | — | 2,8 % | 4 янв. 2004 г. |
18Наблюдать | CVE-2005-4485Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or Hiatek · projectapp · CWE-79 | Средняя4,3 | — | 2,7 % | 22 дек. 2005 г. |
18Наблюдать | CVE-2005-4483Proof of concept | Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script oiatek · siteenable | Средняя4,3 | — | 1,7 % | 22 дек. 2005 г. |
18Наблюдать | CVE-2005-4484Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or iatek · intranetapp | Средняя4,3 | — | 1,7 % | 22 дек. 2005 г. |
17Наблюдать | CVE-2005-0949Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script iatek · portalapp | Средняя4,3 | — | 1,4 % | 2 мая 2005 г. |
17Наблюдать | CVE-2005-1012Эксплойта нет | Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contiatek · siteenable | Средняя4,3 | — | 1,2 % | 2 мая 2005 г. |
- CVE-2002-165941В плане
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %iatek · portalapp31 дек. 2002 г.
- CVE-2005-101131Наблюдать
SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %iatek · siteenable2 мая 2005 г.
- CVE-2005-094830Наблюдать
SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parame
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iatek · portalapp2 мая 2005 г.
- CVE-2008-143030Наблюдать
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iatek · aspapp20 мар. 2008 г.
- CVE-2005-448228Наблюдать
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or
СредняяCVSS 6,8Proof of conceptEPSS 2 %iatek · portalapp22 дек. 2005 г.
- CVE-2004-178621Наблюдать
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensi
СредняяCVSS 5,0Proof of conceptEPSS 3 %iatek · portalapp4 янв. 2004 г.
- CVE-2005-448518Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or H
СредняяCVSS 4,3Proof of conceptEPSS 3 %iatek · projectapp22 дек. 2005 г.
- CVE-2005-448318Наблюдать
Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script o
СредняяCVSS 4,3Proof of conceptEPSS 2 %iatek · siteenable22 дек. 2005 г.
- CVE-2005-448418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 2 %iatek · intranetapp22 дек. 2005 г.
- CVE-2005-094917Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %iatek · portalapp2 мая 2005 г.
- CVE-2005-101217Наблюдать
Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the cont
СредняяCVSS 4,3Эксплойта нетEPSS 1 %iatek · siteenable2 мая 2005 г.