Записи pixelpost
17 опубликованных записей вендора pixelpost.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2009-4899Эксплойта нет | pixelpost 1.7.1 has SQL injectionpixelpost · pixelpost · CWE-89 | Критическая9,8 | — | 1,3 % | 28 окт. 2019 г. |
35Наблюдать | CVE-2010-3305Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.pixelpost · pixelpost · CWE-352 | Высокая8,8 | — | 1,0 % | 12 нояб. 2019 г. |
30Наблюдать | CVE-2006-1104Эксплойта нет | Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) pixelpost · pixelpost | Высокая7,5 | — | 1,5 % | 9 мар. 2006 г. |
29Наблюдать | CVE-2018-0604Эксплойта нет | Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.pixelpost · pixelpost | Высокая7,2 | — | 1,8 % | 26 июн. 2018 г. |
28Наблюдать | CVE-2008-3365Proof of concept | Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to ipixelpost · pixelpost · CWE-22 | Средняя6,8 | — | 3,8 % | 30 июл. 2008 г. |
28Наблюдать | CVE-2008-0358Proof of concept | SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id paramepixelpost · pixelpost · CWE-89 | Средняя6,8 | — | 2,2 % | 18 янв. 2008 г. |
28Наблюдать | CVE-2018-0606Эксплойта нет | SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via pixelpost · pixelpost · CWE-89 | Высокая7,2 | — | 1,1 % | 26 июн. 2018 г. |
26Наблюдать | CVE-2011-1100Proof of concept | Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commapixelpost · pixelpost · CWE-89 | Средняя6,5 | — | 1,3 % | 25 февр. 2011 г. |
24Наблюдать | CVE-2009-4900Эксплойта нет | pixelpost 1.7.1 has XSSpixelpost · pixelpost · CWE-79 | Средняя6,1 | — | 1,0 % | 28 окт. 2019 г. |
24Наблюдать | CVE-2018-0605Эксплойта нет | Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecpixelpost · pixelpost · CWE-79 | Средняя6,1 | — | 0,8 % | 26 июн. 2018 г. |
21Наблюдать | CVE-2006-1105Эксплойта нет | Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, wpixelpost · pixelpost | Средняя5,0 | — | 1,7 % | 9 мар. 2006 г. |
20Наблюдать | CVE-2006-2890Эксплойта нет | Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct otherpixelpost · pixelpost | Средняя5,1 | — | 1,5 % | 7 июн. 2006 г. |
20Наблюдать | CVE-2011-3792Эксплойта нет | Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pixelpost · pixelpost · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
20Наблюдать | CVE-2006-2889Proof of concept | Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commanpixelpost · pixelpost | Средняя5,1 | — | 1,1 % | 7 июн. 2006 г. |
18Наблюдать | CVE-2006-0409Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script orpixelpost · photoblog | Средняя4,3 | — | 2,0 % | 24 янв. 2006 г. |
18Наблюдать | CVE-2006-1106Эксплойта нет | Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML pixelpost · pixelpost | Средняя4,3 | — | 2,0 % | 9 мар. 2006 г. |
11Наблюдать | CVE-2006-2891Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary Hpixelpost · pixelpost | Низкая2,6 | — | 1,9 % | 7 июн. 2006 г. |
- CVE-2009-489939Наблюдать
pixelpost 1.7.1 has SQL injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pixelpost · pixelpost28 окт. 2019 г.
- CVE-2010-330535Наблюдать
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pixelpost · pixelpost12 нояб. 2019 г.
- CVE-2006-110430Наблюдать
Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %pixelpost · pixelpost9 мар. 2006 г.
- CVE-2018-060429Наблюдать
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %pixelpost · pixelpost26 июн. 2018 г.
- CVE-2008-336528Наблюдать
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to i
СредняяCVSS 6,8Proof of conceptEPSS 4 %pixelpost · pixelpost30 июл. 2008 г.
- CVE-2008-035828Наблюдать
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parame
СредняяCVSS 6,8Proof of conceptEPSS 2 %pixelpost · pixelpost18 янв. 2008 г.
- CVE-2018-060628Наблюдать
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %pixelpost · pixelpost26 июн. 2018 г.
- CVE-2011-110026Наблюдать
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL comma
СредняяCVSS 6,5Proof of conceptEPSS 1 %pixelpost · pixelpost25 февр. 2011 г.
- CVE-2009-490024Наблюдать
pixelpost 1.7.1 has XSS
СредняяCVSS 6,1Эксплойта нетEPSS 1 %pixelpost · pixelpost28 окт. 2019 г.
- CVE-2018-060524Наблюдать
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspec
СредняяCVSS 6,1Эксплойта нетEPSS 1 %pixelpost · pixelpost26 июн. 2018 г.
- CVE-2006-110521Наблюдать
Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, w
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pixelpost · pixelpost9 мар. 2006 г.
- CVE-2006-289020Наблюдать
Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct other
СредняяCVSS 5,1Эксплойта нетEPSS 1 %pixelpost · pixelpost7 июн. 2006 г.
- CVE-2011-379220Наблюдать
Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pixelpost · pixelpost23 сент. 2011 г.
- CVE-2006-288920Наблюдать
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL comman
СредняяCVSS 5,1Proof of conceptEPSS 1 %pixelpost · pixelpost7 июн. 2006 г.
- CVE-2006-040918Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 2 %pixelpost · photoblog24 янв. 2006 г.
- CVE-2006-110618Наблюдать
Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 2 %pixelpost · pixelpost9 мар. 2006 г.
- CVE-2006-289111Наблюдать
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary H
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %pixelpost · pixelpost7 июн. 2006 г.