Записи nexusphp project
16 опубликованных записей вендора nexusphp project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2017-12776Эксплойта нет | SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport paramnexusphp project · nexusphp · CWE-89 | Критическая9,8 | — | 1,4 % | 18 авг. 2017 г. |
39Наблюдать | CVE-2017-12909Эксплойта нет | SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parametenexusphp project · nexusphp · CWE-89 | Критическая9,8 | — | 1,4 % | 17 авг. 2017 г. |
39Наблюдать | CVE-2017-12910Эксплойта нет | SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.nexusphp project · nexusphp · CWE-89 | Критическая9,8 | — | 1,3 % | 17 авг. 2017 г. |
39Наблюдать | CVE-2017-12908Эксплойта нет | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr paranexusphp project · nexusphp · CWE-89 | Критическая9,8 | — | 1,3 % | 17 авг. 2017 г. |
39Наблюдать | CVE-2017-14512Эксплойта нет | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability thnexusphp project · nexusphp · CWE-89 | Критическая9,8 | — | 1,1 % | 17 сент. 2017 г. |
35Наблюдать | CVE-2017-12838Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests tnexusphp project · nexusphp · CWE-352 | Высокая8,8 | — | 0,6 % | 7 сент. 2017 г. |
24Наблюдать | CVE-2017-12792Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administranexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 1,2 % | 2 окт. 2017 г. |
24Наблюдать | CVE-2017-15305Эксплойта нет | XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,9 % | 14 окт. 2017 г. |
24Наблюдать | CVE-2017-12906Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_Inexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,8 % | 7 сент. 2017 г. |
24Наблюдать | CVE-2017-14347Эксплойта нет | NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 12 сент. 2017 г. |
24Наблюдать | CVE-2017-12680Эксплойта нет | Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 18 авг. 2017 г. |
24Наблюдать | CVE-2017-12907Эксплойта нет | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 17 авг. 2017 г. |
24Наблюдать | CVE-2017-12798Эксплойта нет | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 10 авг. 2017 г. |
24Наблюдать | CVE-2017-12655Эксплойта нет | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 7 авг. 2017 г. |
24Наблюдать | CVE-2017-14534Эксплойта нет | Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,7 % | 18 сент. 2017 г. |
24Наблюдать | CVE-2017-12777Эксплойта нет | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.nexusphp project · nexusphp · CWE-79 | Средняя6,1 | — | 0,6 % | 9 авг. 2017 г. |
- CVE-2017-1277639Наблюдать
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport param
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp18 авг. 2017 г.
- CVE-2017-1290939Наблюдать
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid paramete
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp17 авг. 2017 г.
- CVE-2017-1291039Наблюдать
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp17 авг. 2017 г.
- CVE-2017-1290839Наблюдать
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr para
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp17 авг. 2017 г.
- CVE-2017-1451239Наблюдать
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability th
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp17 сент. 2017 г.
- CVE-2017-1283835Наблюдать
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests t
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nexusphp project · nexusphp7 сент. 2017 г.
- CVE-2017-1279224Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administra
СредняяCVSS 6,1Proof of conceptEPSS 1 %nexusphp project · nexusphp2 окт. 2017 г.
- CVE-2017-1530524Наблюдать
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp14 окт. 2017 г.
- CVE-2017-1290624Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_I
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp7 сент. 2017 г.
- CVE-2017-1434724Наблюдать
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp12 сент. 2017 г.
- CVE-2017-1268024Наблюдать
Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp18 авг. 2017 г.
- CVE-2017-1290724Наблюдать
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp17 авг. 2017 г.
- CVE-2017-1279824Наблюдать
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp10 авг. 2017 г.
- CVE-2017-1265524Наблюдать
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp7 авг. 2017 г.
- CVE-2017-1453424Наблюдать
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp18 сент. 2017 г.
- CVE-2017-1277724Наблюдать
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nexusphp project · nexusphp9 авг. 2017 г.