Записи jce-tech
11 опубликованных записей вендора jce-tech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-16 Configuration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2010-0375Proof of concept | SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrajce-tech · php calendars script · CWE-89 | Высокая7,5 | — | 1,0 % | 21 янв. 2010 г. |
30Наблюдать | CVE-2010-2461Proof of concept | SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store jce-tech · overstock script · CWE-89 | Высокая7,5 | — | 1,0 % | 25 июн. 2010 г. |
30Наблюдать | CVE-2010-2460Proof of concept | SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitraryjce-tech · shareasale script · CWE-89 | Высокая7,5 | — | 1,0 % | 25 июн. 2010 г. |
21Наблюдать | CVE-2010-0380Proof of concept | install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify applicjce-tech · php calendars script · CWE-16 | Средняя5,0 | — | 2,0 % | 22 янв. 2010 г. |
17Наблюдать | CVE-2009-3195Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary wejce-tech · auction rss content script · CWE-79 | Средняя4,3 | — | 1,5 % | 15 сент. 2009 г. |
17Наблюдать | CVE-2010-0376Proof of concept | Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to injce-tech · php calendars script · CWE-79 | Средняя4,3 | — | 1,5 % | 21 янв. 2010 г. |
17Наблюдать | CVE-2009-3194Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script ojce-tech · searchfeed script · CWE-79 | Средняя4,3 | — | 1,5 % | 15 сент. 2009 г. |
17Наблюдать | CVE-2009-3196Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script orjce-tech · php video script · CWE-79 | Средняя4,3 | — | 1,5 % | 15 сент. 2009 г. |
17Наблюдать | CVE-2014-8752Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote attacjce-tech · video niche script · CWE-79 | Средняя4,3 | — | 1,1 % | 31 дек. 2014 г. |
17Наблюдать | CVE-2009-3198Эксплойта нет | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to injce-tech · affiliate master datafeed parser · CWE-79 | Средняя4,3 | — | 1,1 % | 15 сент. 2009 г. |
17Наблюдать | CVE-2009-3197Эксплойта нет | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP Calendars Script allows remote attackers to inject arbitrary web scrijce-tech · php calendars script · CWE-79 | Средняя4,3 | — | 1,1 % | 15 сент. 2009 г. |
- CVE-2010-037530Наблюдать
SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitra
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jce-tech · php calendars script21 янв. 2010 г.
- CVE-2010-246130Наблюдать
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jce-tech · overstock script25 июн. 2010 г.
- CVE-2010-246030Наблюдать
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jce-tech · shareasale script25 июн. 2010 г.
- CVE-2010-038021Наблюдать
install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify applic
СредняяCVSS 5,0Proof of conceptEPSS 2 %jce-tech · php calendars script22 янв. 2010 г.
- CVE-2009-319517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary we
СредняяCVSS 4,3Proof of conceptEPSS 2 %jce-tech · auction rss content script15 сент. 2009 г.
- CVE-2010-037617Наблюдать
Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to in
СредняяCVSS 4,3Proof of conceptEPSS 1 %jce-tech · php calendars script21 янв. 2010 г.
- CVE-2009-319417Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script o
СредняяCVSS 4,3Proof of conceptEPSS 1 %jce-tech · searchfeed script15 сент. 2009 г.
- CVE-2009-319617Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 1 %jce-tech · php video script15 сент. 2009 г.
- CVE-2014-875217Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote attac
СредняяCVSS 4,3Эксплойта нетEPSS 1 %jce-tech · video niche script31 дек. 2014 г.
- CVE-2009-319817Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to in
СредняяCVSS 4,3Эксплойта нетEPSS 1 %jce-tech · affiliate master datafeed parser15 сент. 2009 г.
- CVE-2009-319717Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP Calendars Script allows remote attackers to inject arbitrary web scri
СредняяCVSS 4,3Эксплойта нетEPSS 1 %jce-tech · php calendars script15 сент. 2009 г.