Записи phpgedview
17 опубликованных записей вендора phpgedview.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 11,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2004-0030Proof of concept | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 alphpgedview · phpgedview · CWE-829 | Критическая9,8 | — | 7,3 % | 20 янв. 2004 г. |
41В плане | CVE-2008-2064Эксплойта нет | Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flawphpgedview · phpgedview | Критическая10,0 | — | 1,9 % | 2 мая 2008 г. |
32Наблюдать | CVE-2004-0128Proof of concept | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execphpgedview · phpgedview | Высокая7,5 | — | 8,3 % | 3 мар. 2004 г. |
32Наблюдать | CVE-2005-4468Proof of concept | PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary codphpgedview · phpgedview | Высокая7,5 | — | 7,8 % | 21 дек. 2005 г. |
31Наблюдать | CVE-2005-4469Эксплойта нет | Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code vphpgedview · phpgedview | Высокая7,5 | — | 2,7 % | 21 дек. 2005 г. |
31Наблюдать | CVE-2004-0127Эксплойта нет | Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary filesphpgedview · phpgedview | Высокая7,5 | — | 2,2 % | 3 мар. 2004 г. |
31Наблюдать | CVE-2004-0065Эксплойта нет | Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2phpgedview · phpgedview | Высокая7,5 | — | 1,9 % | 17 февр. 2004 г. |
30Наблюдать | CVE-2004-0031Эксплойта нет | PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconphpgedview · phpgedview | Высокая7,5 | — | 1,5 % | 20 янв. 2004 г. |
29Наблюдать | CVE-2011-0405Proof of concept | Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows rphpgedview · phpgedview · CWE-22 | Средняя6,8 | — | 6,1 % | 10 янв. 2011 г. |
28Наблюдать | CVE-2004-0032Proof of concept | Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script viphpgedview · phpgedview | Средняя6,8 | — | 1,8 % | 20 янв. 2004 г. |
21Наблюдать | CVE-2005-4467Proof of concept | Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrarphpgedview · phpgedview | Средняя5,0 | — | 4,7 % | 21 дек. 2005 г. |
21Наблюдать | CVE-2004-0033Proof of concept | admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.phpgedview · phpgedview | Средняя5,0 | — | 2,8 % | 20 янв. 2004 г. |
20Наблюдать | CVE-2004-0130Эксплойта нет | login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does phpgedview · phpgedview | Средняя5,0 | — | 1,5 % | 3 мар. 2004 г. |
20Наблюдать | CVE-2004-0066Эксплойта нет | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (phpgedview · phpgedview | Средняя5,0 | — | 1,4 % | 17 февр. 2004 г. |
20Наблюдать | CVE-2011-3778Эксплойта нет | PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installationphpgedview · phpgedview · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
18Наблюдать | CVE-2004-0067Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script phpgedview · phpgedview · CWE-79 | Средняя4,3 | — | 3,1 % | 17 февр. 2004 г. |
17Наблюдать | CVE-2007-5051Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via thphpgedview · phpgedview · CWE-79 | Средняя4,3 | — | 1,1 % | 23 сент. 2007 г. |
- CVE-2004-003041В плане
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al
КритическаяCVSS 9,8Proof of conceptEPSS 7 %phpgedview · phpgedview20 янв. 2004 г.
- CVE-2008-206441В плане
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %phpgedview · phpgedview2 мая 2008 г.
- CVE-2004-012832Наблюдать
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to exec
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %phpgedview · phpgedview3 мар. 2004 г.
- CVE-2005-446832Наблюдать
PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary cod
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %phpgedview · phpgedview21 дек. 2005 г.
- CVE-2005-446931Наблюдать
Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code v
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %phpgedview · phpgedview21 дек. 2005 г.
- CVE-2004-012731Наблюдать
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpgedview · phpgedview3 мар. 2004 г.
- CVE-2004-006531Наблюдать
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpgedview · phpgedview17 февр. 2004 г.
- CVE-2004-003130Наблюдать
PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editcon
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpgedview · phpgedview20 янв. 2004 г.
- CVE-2011-040529Наблюдать
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows r
СредняяCVSS 6,8Proof of conceptEPSS 6 %phpgedview · phpgedview10 янв. 2011 г.
- CVE-2004-003228Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script vi
СредняяCVSS 6,8Proof of conceptEPSS 2 %phpgedview · phpgedview20 янв. 2004 г.
- CVE-2005-446721Наблюдать
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrar
СредняяCVSS 5,0Proof of conceptEPSS 5 %phpgedview · phpgedview21 дек. 2005 г.
- CVE-2004-003321Наблюдать
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.
СредняяCVSS 5,0Proof of conceptEPSS 3 %phpgedview · phpgedview20 янв. 2004 г.
- CVE-2004-013020Наблюдать
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpgedview · phpgedview3 мар. 2004 г.
- CVE-2004-006620Наблюдать
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpgedview · phpgedview17 февр. 2004 г.
- CVE-2011-377820Наблюдать
PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpgedview · phpgedview23 сент. 2011 г.
- CVE-2004-006718Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script
СредняяCVSS 4,3Proof of conceptEPSS 3 %phpgedview · phpgedview17 февр. 2004 г.
- CVE-2007-505117Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via th
СредняяCVSS 4,3Эксплойта нетEPSS 1 %phpgedview · phpgedview23 сент. 2007 г.