Записи php-stats
12 опубликованных записей вендора php-stats.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2006-7173Proof of concept | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP cphp-stats · php-stats | Критическая10,0 | — | 3,8 % | 20 мар. 2007 г. |
41В плане | CVE-2006-1085Эксплойта нет | admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbiphp-stats · php-stats | Критическая10,0 | — | 3,5 % | 8 мар. 2006 г. |
41В плане | CVE-2007-5452Proof of concept | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands php-stats · php-stats · CWE-89 | Критическая10,0 | — | 2,9 % | 14 окт. 2007 г. |
35Наблюдать | CVE-2007-5453Proof of concept | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing php-stats · php-stats · CWE-94 | Высокая8,5 | — | 3,9 % | 14 окт. 2007 г. |
31Наблюдать | CVE-2006-7172Proof of concept | Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitraryphp-stats · php-stats | Высокая7,5 | — | 2,3 % | 20 мар. 2007 г. |
31Наблюдать | CVE-2006-1083Эксплойта нет | Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary php-stats · php-stats | Высокая7,5 | — | 2,2 % | 8 мар. 2006 г. |
30Наблюдать | CVE-2006-1084Эксплойта нет | Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) thephp-stats · php-stats | Высокая7,5 | — | 1,5 % | 8 мар. 2006 г. |
27Наблюдать | CVE-2006-1087Эксплойта нет | Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authentiphp-stats · php-stats | Средняя6,5 | — | 1,8 % | 8 мар. 2006 г. |
21Наблюдать | CVE-2006-1088Эксплойта нет | PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, wphp-stats · php-stats | Средняя5,0 | — | 1,8 % | 8 мар. 2006 г. |
18Наблюдать | CVE-2007-4334Proof of concept | Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats | Средняя4,3 | — | 1,8 % | 14 авг. 2007 г. |
17Наблюдать | CVE-2007-4917Proof of concept | Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTMLphp-stats · php-stats · CWE-79 | Средняя4,3 | — | 1,5 % | 17 сент. 2007 г. |
17Наблюдать | CVE-2008-6212Proof of concept | Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats · CWE-79 | Средняя4,3 | — | 1,5 % | 19 февр. 2009 г. |
- CVE-2006-717341В плане
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP c
КритическаяCVSS 10,0Proof of conceptEPSS 4 %php-stats · php-stats20 мар. 2007 г.
- CVE-2006-108541В плане
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbi
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %php-stats · php-stats8 мар. 2006 г.
- CVE-2007-545241В плане
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands
КритическаяCVSS 10,0Proof of conceptEPSS 3 %php-stats · php-stats14 окт. 2007 г.
- CVE-2007-545335Наблюдать
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing
ВысокаяCVSS 8,5Proof of conceptEPSS 4 %php-stats · php-stats14 окт. 2007 г.
- CVE-2006-717231Наблюдать
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php-stats · php-stats20 мар. 2007 г.
- CVE-2006-108331Наблюдать
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php-stats · php-stats8 мар. 2006 г.
- CVE-2006-108430Наблюдать
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php-stats · php-stats8 мар. 2006 г.
- CVE-2006-108727Наблюдать
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenti
СредняяCVSS 6,5Эксплойта нетEPSS 2 %php-stats · php-stats8 мар. 2006 г.
- CVE-2006-108821Наблюдать
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, w
СредняяCVSS 5,0Эксплойта нетEPSS 2 %php-stats · php-stats8 мар. 2006 г.
- CVE-2007-433418Наблюдать
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Proof of conceptEPSS 2 %php-stats · php-stats14 авг. 2007 г.
- CVE-2007-491717Наблюдать
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 1 %php-stats · php-stats17 сент. 2007 г.
- CVE-2008-621217Наблюдать
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Proof of conceptEPSS 1 %php-stats · php-stats19 февр. 2009 г.