Записи jelsoft
60 опубликованных записей вендора jelsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 1,7 %
- Pre-auth RCE
- 19
- С записью об исправлении
- 1,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-189 Numeric Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
60 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2005-0511Готовый эксплойт | misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitraryjelsoft · vbulletin | Высокая7,5 | — | 35,8 % | 21 февр. 2005 г. |
38Наблюдать | CVE-2007-4120Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URLjelsoft · vbulletin | Критическая9,3 | — | 2,1 % | 1 авг. 2007 г. |
34Наблюдать | CVE-2007-2911Эксплойта нет | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to executjelsoft · vbulletin | Высокая8,5 | — | 1,3 % | 30 мая 2007 г. |
33Наблюдать | CVE-2002-1660Proof of concept | calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parametjelsoft · vbulletin · CWE-78 | Высокая7,5 | — | 11,1 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2005-3019Proof of concept | Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) requesjelsoft · vbulletin | Высокая7,5 | — | 3,9 % | 21 сент. 2005 г. |
31Наблюдать | CVE-2001-0475Эксплойта нет | index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote ajelsoft · vbulletin | Высокая7,5 | — | 2,8 % | 27 июн. 2001 г. |
31Наблюдать | CVE-2006-4271Эксплойта нет | PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary Pjelsoft · vbulletin | Высокая7,5 | — | 2,1 % | 21 авг. 2006 г. |
31Наблюдать | CVE-2006-1382Эксплойта нет | PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remjelsoft · impex | Высокая7,5 | — | 1,9 % | 24 мар. 2006 г. |
31Наблюдать | CVE-2004-2695Эксплойта нет | SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows rjelsoft · vbulletin · CWE-89 | Высокая7,5 | — | 1,9 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2006-4272Эксплойта нет | Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vijelsoft · vbulletin | Высокая7,5 | — | 1,5 % | 21 авг. 2006 г. |
30Наблюдать | CVE-2007-1292Proof of concept | SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote autjelsoft · vbulletin | Высокая7,5 | — | 1,3 % | 6 мар. 2007 г. |
30Наблюдать | CVE-2005-3024Эксплойта нет | Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ajelsoft · vbulletin | Высокая7,5 | — | 1,2 % | 21 сент. 2005 г. |
30Наблюдать | CVE-2005-3022Эксплойта нет | Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ajelsoft · vbulletin | Высокая7,5 | — | 1,2 % | 21 сент. 2005 г. |
30Наблюдать | CVE-2007-3196Proof of concept | SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL comjelsoft · vbsupport integrated ticket system | Высокая7,5 | — | 1,2 % | 12 июн. 2007 г. |
30Наблюдать | CVE-2006-2018Эксплойта нет | SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parjelsoft · vbulletin | Высокая7,5 | — | 1,2 % | 25 апр. 2006 г. |
30Наблюдать | CVE-2006-5104Proof of concept | SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatjelsoft · vbulletin | Высокая7,5 | — | 1,1 % | 3 окт. 2006 г. |
30Наблюдать | CVE-2004-1515Proof of concept | SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statemejelsoft · vbulletin | Высокая7,5 | — | 1,0 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2007-3197Эксплойта нет | SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspjelsoft · vbsupport integrated ticket system | Высокая7,5 | — | 1,0 % | 12 июн. 2007 г. |
28Наблюдать | CVE-2006-6779Proof of concept | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF filejelsoft · vbulletin | Средняя6,8 | — | 3,5 % | 27 дек. 2006 г. |
28Наблюдать | CVE-2006-6040Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrajelsoft · vbulletin | Средняя6,8 | — | 2,2 % | 21 нояб. 2006 г. |
28Наблюдать | CVE-2006-4273Proof of concept | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTMLjelsoft · vbulletin | Средняя6,8 | — | 2,2 % | 21 авг. 2006 г. |
27Наблюдать | CVE-2006-2335Эксплойта нет | Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administratorjelsoft · vbulletin | Средняя6,5 | — | 3,4 % | 11 мая 2006 г. |
27Наблюдать | CVE-2003-0295Proof of concept | Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script anjelsoft · vbulletin | Средняя6,8 | — | 1,6 % | 16 июн. 2003 г. |
24Наблюдать | CVE-2007-1573Эксплойта нет | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitjelsoft · vbulletin · CWE-89 | Средняя6,0 | — | 0,9 % | 21 мар. 2007 г. |
23Наблюдать | CVE-2007-3326Эксплойта нет | Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .jelsoft · vbulletin | Средняя5,8 | — | 1,2 % | 21 июн. 2007 г. |
- CVE-2005-051141В плане
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Готовый эксплойтEPSS 36 %jelsoft · vbulletin21 февр. 2005 г.
- CVE-2007-412038Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %jelsoft · vbulletin1 авг. 2007 г.
- CVE-2007-291134Наблюдать
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execut
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %jelsoft · vbulletin30 мая 2007 г.
- CVE-2002-166033Наблюдать
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %jelsoft · vbulletin31 дек. 2002 г.
- CVE-2005-301931Наблюдать
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) reques
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %jelsoft · vbulletin21 сент. 2005 г.
- CVE-2001-047531Наблюдать
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %jelsoft · vbulletin27 июн. 2001 г.
- CVE-2006-427131Наблюдать
PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary P
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %jelsoft · vbulletin21 авг. 2006 г.
- CVE-2006-138231Наблюдать
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows rem
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %jelsoft · impex24 мар. 2006 г.
- CVE-2004-269531Наблюдать
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows r
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %jelsoft · vbulletin31 дек. 2004 г.
- CVE-2006-427230Наблюдать
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %jelsoft · vbulletin21 авг. 2006 г.
- CVE-2007-129230Наблюдать
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote aut
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jelsoft · vbulletin6 мар. 2007 г.
- CVE-2005-302430Наблюдать
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jelsoft · vbulletin21 сент. 2005 г.
- CVE-2005-302230Наблюдать
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jelsoft · vbulletin21 сент. 2005 г.
- CVE-2007-319630Наблюдать
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL com
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jelsoft · vbsupport integrated ticket system12 июн. 2007 г.
- CVE-2006-201830Наблюдать
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid par
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jelsoft · vbulletin25 апр. 2006 г.
- CVE-2006-510430Наблюдать
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templat
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jelsoft · vbulletin3 окт. 2006 г.
- CVE-2004-151530Наблюдать
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL stateme
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %jelsoft · vbulletin31 дек. 2004 г.
- CVE-2007-319730Наблюдать
SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unsp
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jelsoft · vbsupport integrated ticket system12 июн. 2007 г.
- CVE-2006-677928Наблюдать
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file
СредняяCVSS 6,8Proof of conceptEPSS 4 %jelsoft · vbulletin27 дек. 2006 г.
- CVE-2006-604028Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitra
СредняяCVSS 6,8Proof of conceptEPSS 2 %jelsoft · vbulletin21 нояб. 2006 г.
- CVE-2006-427328Наблюдать
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,8Proof of conceptEPSS 2 %jelsoft · vbulletin21 авг. 2006 г.
- CVE-2006-233527Наблюдать
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrator
СредняяCVSS 6,5Эксплойта нетEPSS 3 %jelsoft · vbulletin11 мая 2006 г.
- CVE-2003-029527Наблюдать
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script an
СредняяCVSS 6,8Proof of conceptEPSS 2 %jelsoft · vbulletin16 июн. 2003 г.
- CVE-2007-157324Наблюдать
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbit
СредняяCVSS 6,0Эксплойта нетEPSS 1 %jelsoft · vbulletin21 мар. 2007 г.
- CVE-2007-332623Наблюдать
Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .
СредняяCVSS 5,8Эксплойта нетEPSS 1 %jelsoft · vbulletin21 июн. 2007 г.