Записи phpwebsite
20 опубликованных записей вендора phpwebsite.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2002-1135Proof of concept | modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_pphpwebsite · phpwebsite | Высокая7,5 | — | 6,6 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2006-1819Эксплойта нет | Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includphpwebsite · phpwebsite | Высокая7,5 | — | 3,9 % | 18 апр. 2006 г. |
31Наблюдать | CVE-2006-5234Proof of concept | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in thphpwebsite · phpwebsite | Высокая7,5 | — | 2,8 % | 10 окт. 2006 г. |
31Наблюдать | CVE-2005-0565Эксплойта нет | The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to refphpwebsite · phpwebsite | Высокая7,5 | — | 1,7 % | 2 мая 2005 г. |
31Наблюдать | CVE-2003-0735Proof of concept | SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,phpwebsite · phpwebsite | Высокая7,5 | — | 1,7 % | 20 окт. 2003 г. |
31Наблюдать | CVE-2003-0738Эксплойта нет | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.phpwebsite · phpwebsite · CWE-134 | Высокая7,8 | — | 1,5 % | 20 окт. 2003 г. |
30Наблюдать | CVE-2004-2322Эксплойта нет | SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrphpwebsite · phpwebsite | Высокая7,5 | — | 1,5 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2004-1654Эксплойта нет | SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commanphpwebsite · phpwebsite | Высокая7,5 | — | 1,3 % | 1 сент. 2004 г. |
30Наблюдать | CVE-2006-0973Proof of concept | SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute aphpwebsite · phpwebsite | Высокая7,5 | — | 1,3 % | 3 мар. 2006 г. |
30Наблюдать | CVE-2006-1330Proof of concept | Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid pphpwebsite · phpwebsite · CWE-89 | Высокая7,5 | — | 1,3 % | 20 мар. 2006 г. |
30Наблюдать | CVE-2005-4792Proof of concept | SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arphpwebsite · phpwebsite | Высокая7,5 | — | 1,1 % | 31 дек. 2005 г. |
28Наблюдать | CVE-2003-0736Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script vphpwebsite · phpwebsite | Средняя6,8 | — | 2,7 % | 20 окт. 2003 г. |
21Наблюдать | CVE-2005-0572Эксплойта нет | index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parametephpwebsite · phpwebsite | Средняя5,0 | — | 2,1 % | 2 мая 2005 г. |
20Наблюдать | CVE-2004-1516Эксплойта нет | CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modifyphpwebsite · phpwebsite | Средняя5,0 | — | 1,6 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2003-0737Эксплойта нет | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, wphpwebsite · phpwebsite | Средняя5,0 | — | 1,3 % | 20 окт. 2003 г. |
18Наблюдать | CVE-2004-1655Proof of concept | Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML viphpwebsite · phpwebsite | Средняя4,3 | — | 2,2 % | 1 сент. 2004 г. |
18Наблюдать | CVE-2002-2178Proof of concept | Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript phpwebsite · phpwebsite | Средняя4,3 | — | 1,7 % | 31 дек. 2002 г. |
18Наблюдать | CVE-2008-0092Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote atphpwebsite · phpwebsite · CWE-79 | Средняя4,3 | — | 1,7 % | 3 янв. 2008 г. |
17Наблюдать | CVE-2002-1807Эксплойта нет | Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript iphpwebsite · phpwebsite | Средняя4,3 | — | 1,2 % | 31 дек. 2002 г. |
17Наблюдать | CVE-2011-4265Эксплойта нет | Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspephpwebsite · phpwebsite · CWE-79 | Средняя4,3 | — | 0,8 % | 8 дек. 2011 г. |
- CVE-2002-113532Наблюдать
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_p
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %phpwebsite · phpwebsite4 окт. 2002 г.
- CVE-2006-181931Наблюдать
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includ
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %phpwebsite · phpwebsite18 апр. 2006 г.
- CVE-2006-523431Наблюдать
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in th
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpwebsite · phpwebsite10 окт. 2006 г.
- CVE-2005-056531Наблюдать
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to ref
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpwebsite · phpwebsite2 мая 2005 г.
- CVE-2003-073531Наблюдать
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phpwebsite · phpwebsite20 окт. 2003 г.
- CVE-2003-073831Наблюдать
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %phpwebsite · phpwebsite20 окт. 2003 г.
- CVE-2004-232230Наблюдать
SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpwebsite · phpwebsite31 дек. 2004 г.
- CVE-2004-165430Наблюдать
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpwebsite · phpwebsite1 сент. 2004 г.
- CVE-2006-097330Наблюдать
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpwebsite · phpwebsite3 мар. 2006 г.
- CVE-2006-133030Наблюдать
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpwebsite · phpwebsite20 мар. 2006 г.
- CVE-2005-479230Наблюдать
SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute ar
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpwebsite · phpwebsite31 дек. 2005 г.
- CVE-2003-073628Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script v
СредняяCVSS 6,8Proof of conceptEPSS 3 %phpwebsite · phpwebsite20 окт. 2003 г.
- CVE-2005-057221Наблюдать
index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module paramete
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpwebsite · phpwebsite2 мая 2005 г.
- CVE-2004-151620Наблюдать
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpwebsite · phpwebsite31 дек. 2004 г.
- CVE-2003-073720Наблюдать
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, w
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpwebsite · phpwebsite20 окт. 2003 г.
- CVE-2004-165518Наблюдать
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Proof of conceptEPSS 2 %phpwebsite · phpwebsite1 сент. 2004 г.
- CVE-2002-217818Наблюдать
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript
СредняяCVSS 4,3Proof of conceptEPSS 2 %phpwebsite · phpwebsite31 дек. 2002 г.
- CVE-2008-009218Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote at
СредняяCVSS 4,3Proof of conceptEPSS 2 %phpwebsite · phpwebsite3 янв. 2008 г.
- CVE-2002-180717Наблюдать
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript i
СредняяCVSS 4,3Эксплойта нетEPSS 1 %phpwebsite · phpwebsite31 дек. 2002 г.
- CVE-2011-426517Наблюдать
Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspe
СредняяCVSS 4,3Эксплойта нетEPSS 1 %phpwebsite · phpwebsite8 дек. 2011 г.