Перейти к содержимому
Noroxi

Записи jetbox

21 опубликованных записей вендора jetbox.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    21 записей
    • CVE-2006-2270
      34Наблюдать

      PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL

      ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

      jetbox · jetbox cms9 мая 2006 г.

    • CVE-2006-4422
      32Наблюдать

      PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arb

      ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

      jetbox · jetbox cms28 авг. 2006 г.

    • CVE-2006-3583
      31Наблюдать

      Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      jetbox · jetbox cms8 авг. 2006 г.

    • CVE-2006-3584
      30Наблюдать

      Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables vi

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      jetbox · jetbox cms8 авг. 2006 г.

    • CVE-2006-4738
      30Наблюдать

      PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      jetbox · jetbox cms13 сент. 2006 г.

    • CVE-2006-3586
      30Наблюдать

      SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to execute arbitrary SQL commands via the (1) frontsession COOKIE

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      jetbox · jetbox cms8 авг. 2006 г.

    • CVE-2006-4737
      30Наблюдать

      SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      jetbox · jetbox cms13 сент. 2006 г.

    • CVE-2007-2685
      30Наблюдать

      Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) v

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      jetbox · jetbox cms21 мая 2007 г.

    • CVE-2007-2732
      28Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1)

      СредняяCVSS 6,8Proof of conceptEPSS 4 %

      jetbox · jetbox cms16 мая 2007 г.

    • CVE-2007-1898
      24Наблюдать

      formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_host

      СредняяCVSS 5,8Proof of conceptEPSS 3 %

      hp · hp-ux16 мая 2007 г.

    • CVE-2007-2733
      24Наблюдать

      Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts vi

      СредняяCVSS 6,0Эксплойта нетEPSS 1 %

      jetbox · jetbox cms16 мая 2007 г.

    • CVE-2008-4651
      24Наблюдать

      Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orde

      СредняяCVSS 6,0Proof of conceptEPSS 1 %

      jetbox · jetbox cms21 окт. 2008 г.

    • CVE-2004-1447
      21Наблюдать

      Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive in

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      jetbox · jetbox one cms31 дек. 2004 г.

    • CVE-2007-2684
      20Наблюдать

      Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      jetbox · jetbox cms21 мая 2007 г.

    • CVE-2006-4740
      20Наблюдать

      Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      jetbox · jetbox cms13 сент. 2006 г.

    • CVE-2004-1448
      19Наблюдать

      Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and exec

      СредняяCVSS 4,6Эксплойта нетEPSS 2 %

      jetbox · jetbox one cms31 дек. 2004 г.

    • CVE-2007-2686
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via t

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      jetbox · jetbox cms22 мая 2007 г.

    • CVE-2006-3585
      18Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1 SR1 allow remote attackers to inject arbitrary web script or HTML via

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      jetbox · jetbox cms8 авг. 2006 г.

    • CVE-2008-6174
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web scr

      СредняяCVSS 4,3Proof of conceptEPSS 1 %

      jetbox · jetbox cms19 февр. 2009 г.

    • CVE-2007-2731
      16Наблюдать

      CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A)

      СредняяCVSS 4,0Эксплойта нетEPSS 2 %

      jetbox · jetbox cms16 мая 2007 г.

    • CVE-2006-4739
      10Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstr

      НизкаяCVSS 2,6Эксплойта нетEPSS 1 %

      jetbox · jetbox cms13 сент. 2006 г.