Перейти к содержимому
Noroxi

Записи phpwebsite

20 опубликованных записей вендора phpwebsite.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
12
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    20 записей
    • CVE-2002-1135
      32Наблюдать

      modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_p

      ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

      phpwebsite · phpwebsite4 окт. 2002 г.

    • CVE-2006-1819
      31Наблюдать

      Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includ

      ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

      phpwebsite · phpwebsite18 апр. 2006 г.

    • CVE-2006-5234
      31Наблюдать

      Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in th

      ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

      phpwebsite · phpwebsite10 окт. 2006 г.

    • CVE-2005-0565
      31Наблюдать

      The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to ref

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpwebsite · phpwebsite2 мая 2005 г.

    • CVE-2003-0735
      31Наблюдать

      SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      phpwebsite · phpwebsite20 окт. 2003 г.

    • CVE-2003-0738
      31Наблюдать

      The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.

      ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

      phpwebsite · phpwebsite20 окт. 2003 г.

    • CVE-2004-2322
      30Наблюдать

      SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitr

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpwebsite · phpwebsite31 дек. 2004 г.

    • CVE-2004-1654
      30Наблюдать

      SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL comman

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      phpwebsite · phpwebsite1 сент. 2004 г.

    • CVE-2006-0973
      30Наблюдать

      SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute a

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      phpwebsite · phpwebsite3 мар. 2006 г.

    • CVE-2006-1330
      30Наблюдать

      Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid p

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      phpwebsite · phpwebsite20 мар. 2006 г.

    • CVE-2005-4792
      30Наблюдать

      SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute ar

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      phpwebsite · phpwebsite31 дек. 2005 г.

    • CVE-2003-0736
      28Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script v

      СредняяCVSS 6,8Proof of conceptEPSS 3 %

      phpwebsite · phpwebsite20 окт. 2003 г.

    • CVE-2005-0572
      21Наблюдать

      index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module paramete

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpwebsite · phpwebsite2 мая 2005 г.

    • CVE-2004-1516
      20Наблюдать

      CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpwebsite · phpwebsite31 дек. 2004 г.

    • CVE-2003-0737
      20Наблюдать

      The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, w

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      phpwebsite · phpwebsite20 окт. 2003 г.

    • CVE-2004-1655
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML vi

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      phpwebsite · phpwebsite1 сент. 2004 г.

    • CVE-2002-2178
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      phpwebsite · phpwebsite31 дек. 2002 г.

    • CVE-2008-0092
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote at

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      phpwebsite · phpwebsite3 янв. 2008 г.

    • CVE-2002-1807
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript i

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      phpwebsite · phpwebsite31 дек. 2002 г.

    • CVE-2011-4265
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspe

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      phpwebsite · phpwebsite8 дек. 2011 г.