Записи phpstore
6 опубликованных записей вендора phpstore.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2008-5493Proof of concept | SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands viphpstore · wholesale · CWE-89 | Высокая7,5 | — | 1,2 % | 12 дек. 2008 г. |
30Наблюдать | CVE-2008-5490Proof of concept | SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id paraphpstore · yahoo answers · CWE-89 | Высокая7,5 | — | 1,2 % | 12 дек. 2008 г. |
27Наблюдать | CVE-2008-6929Proof of concept | Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploadingphpstore · auto classifieds · CWE-264 | Средняя6,5 | — | 3,4 % | 11 авг. 2009 г. |
27Наблюдать | CVE-2008-6930Proof of concept | Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a fiphpstore · real estate · CWE-264 | Средняя6,5 | — | 3,4 % | 11 авг. 2009 г. |
27Наблюдать | CVE-2008-6931Proof of concept | Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code bphpstore · phpcareers · CWE-264 | Средняя6,5 | — | 3,4 % | 11 авг. 2009 г. |
27Наблюдать | CVE-2008-6928Proof of concept | Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploaphpstore · complete classifieds · CWE-264 | Средняя6,5 | — | 3,3 % | 11 авг. 2009 г. |
- CVE-2008-549330Наблюдать
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpstore · wholesale12 дек. 2008 г.
- CVE-2008-549030Наблюдать
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id para
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpstore · yahoo answers12 дек. 2008 г.
- CVE-2008-692927Наблюдать
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading
СредняяCVSS 6,5Proof of conceptEPSS 3 %phpstore · auto classifieds11 авг. 2009 г.
- CVE-2008-693027Наблюдать
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a fi
СредняяCVSS 6,5Proof of conceptEPSS 3 %phpstore · real estate11 авг. 2009 г.
- CVE-2008-693127Наблюдать
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code b
СредняяCVSS 6,5Proof of conceptEPSS 3 %phpstore · phpcareers11 авг. 2009 г.
- CVE-2008-692827Наблюдать
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploa
СредняяCVSS 6,5Proof of conceptEPSS 3 %phpstore · complete classifieds11 авг. 2009 г.