Перейти к содержимому
Noroxi

Записи jelsoft

60 опубликованных записей вендора jelsoft.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 1,7 %
Pre-auth RCE
19
С записью об исправлении
1,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

60 записей
  • CVE-2005-0511
    41В плане

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 36 %

    jelsoft · vbulletin21 февр. 2005 г.

  • CVE-2007-4120
    38Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    jelsoft · vbulletin1 авг. 2007 г.

  • CVE-2007-2911
    34Наблюдать

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execut

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    jelsoft · vbulletin30 мая 2007 г.

  • CVE-2002-1660
    33Наблюдать

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command paramet

    ВысокаяCVSS 7,5Proof of conceptEPSS 11 %

    jelsoft · vbulletin31 дек. 2002 г.

  • CVE-2005-3019
    31Наблюдать

    Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) reques

    ВысокаяCVSS 7,5Proof of conceptEPSS 4 %

    jelsoft · vbulletin21 сент. 2005 г.

  • CVE-2001-0475
    31Наблюдать

    index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    jelsoft · vbulletin27 июн. 2001 г.

  • CVE-2006-4271
    31Наблюдать

    PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary P

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    jelsoft · vbulletin21 авг. 2006 г.

  • CVE-2006-1382
    31Наблюдать

    PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows rem

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    jelsoft · impex24 мар. 2006 г.

  • CVE-2004-2695
    31Наблюдать

    SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows r

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    jelsoft · vbulletin31 дек. 2004 г.

  • CVE-2006-4272
    30Наблюдать

    Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    jelsoft · vbulletin21 авг. 2006 г.

  • CVE-2007-1292
    30Наблюдать

    SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote aut

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    jelsoft · vbulletin6 мар. 2007 г.

  • CVE-2005-3024
    30Наблюдать

    Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jelsoft · vbulletin21 сент. 2005 г.

  • CVE-2005-3022
    30Наблюдать

    Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jelsoft · vbulletin21 сент. 2005 г.

  • CVE-2007-3196
    30Наблюдать

    SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL com

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    jelsoft · vbsupport integrated ticket system12 июн. 2007 г.

  • CVE-2006-2018
    30Наблюдать

    SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid par

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jelsoft · vbulletin25 апр. 2006 г.

  • CVE-2006-5104
    30Наблюдать

    SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templat

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    jelsoft · vbulletin3 окт. 2006 г.

  • CVE-2004-1515
    30Наблюдать

    SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL stateme

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    jelsoft · vbulletin31 дек. 2004 г.

  • CVE-2007-3197
    30Наблюдать

    SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unsp

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jelsoft · vbsupport integrated ticket system12 июн. 2007 г.

  • CVE-2006-6779
    28Наблюдать

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file

    СредняяCVSS 6,8Proof of conceptEPSS 4 %

    jelsoft · vbulletin27 дек. 2006 г.

  • CVE-2006-6040
    28Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitra

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    jelsoft · vbulletin21 нояб. 2006 г.

  • CVE-2006-4273
    28Наблюдать

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    jelsoft · vbulletin21 авг. 2006 г.

  • CVE-2006-2335
    27Наблюдать

    Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrator

    СредняяCVSS 6,5Эксплойта нетEPSS 3 %

    jelsoft · vbulletin11 мая 2006 г.

  • CVE-2003-0295
    27Наблюдать

    Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script an

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    jelsoft · vbulletin16 июн. 2003 г.

  • CVE-2007-1573
    24Наблюдать

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbit

    СредняяCVSS 6,0Эксплойта нетEPSS 1 %

    jelsoft · vbulletin21 мар. 2007 г.

  • CVE-2007-3326
    23Наблюдать

    Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .

    СредняяCVSS 5,8Эксплойта нетEPSS 1 %

    jelsoft · vbulletin21 июн. 2007 г.