Записи plogger
10 опубликованных записей вендора plogger.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-254 7PK - Security Features1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2005-4573Proof of concept | PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a plogger · plogger · CWE-94 | Высокая7,5 | — | 11,7 % | 29 дек. 2005 г. |
33Наблюдать | CVE-2014-2223Proof of concept | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to exeplogger · plogger · CWE-94 | Высокая7,5 | — | 10,0 % | 11 сент. 2014 г. |
31Наблюдать | CVE-2007-6587Proof of concept | SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parplogger · plogger · CWE-89 | Высокая7,5 | — | 3,4 % | 28 дек. 2007 г. |
31Наблюдать | CVE-2008-3563Proof of concept | Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checkplogger · plogger · CWE-89 | Высокая7,5 | — | 2,4 % | 10 авг. 2008 г. |
30Наблюдать | CVE-2007-2277Эксплойта нет | Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.plogger · plogger · CWE-287 | Высокая7,5 | — | 1,4 % | 25 апр. 2007 г. |
30Наблюдать | CVE-2012-5289Эксплойта нет | Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (plogger · plogger · CWE-89 | Высокая7,5 | — | 1,3 % | 4 окт. 2012 г. |
30Наблюдать | CVE-2005-4246Proof of concept | SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameterplogger · plogger · CWE-89 | Высокая7,5 | — | 1,1 % | 14 дек. 2005 г. |
30Наблюдать | CVE-2006-2157Эксплойта нет | SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via theplogger · plogger · CWE-89 | Высокая7,5 | — | 1,1 % | 3 мая 2006 г. |
20Наблюдать | CVE-2014-2224Эксплойта нет | Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote atplogger · plogger · CWE-254 | Средняя5,0 | — | 1,4 % | 29 дек. 2014 г. |
18Наблюдать | CVE-2005-4247Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script oplogger · plogger · CWE-79 | Средняя4,3 | — | 1,7 % | 14 дек. 2005 г. |
- CVE-2005-457334Наблюдать
PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %plogger · plogger29 дек. 2005 г.
- CVE-2014-222333Наблюдать
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to exe
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %plogger · plogger11 сент. 2014 г.
- CVE-2007-658731Наблюдать
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id par
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %plogger · plogger28 дек. 2007 г.
- CVE-2008-356331Наблюдать
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the check
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %plogger · plogger10 авг. 2008 г.
- CVE-2007-227730Наблюдать
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plogger · plogger25 апр. 2007 г.
- CVE-2012-528930Наблюдать
Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plogger · plogger4 окт. 2012 г.
- CVE-2005-424630Наблюдать
SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %plogger · plogger14 дек. 2005 г.
- CVE-2006-215730Наблюдать
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %plogger · plogger3 мая 2006 г.
- CVE-2014-222420Наблюдать
Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote at
СредняяCVSS 5,0Эксплойта нетEPSS 1 %plogger · plogger29 дек. 2014 г.
- CVE-2005-424718Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script o
СредняяCVSS 4,3Proof of conceptEPSS 2 %plogger · plogger14 дек. 2005 г.