Записи preprojects
29 опубликованных записей вендора preprojects.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 18
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')18
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-255 Credentials Management Errors2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-6231Proof of concept | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and preprojects · pre classified listings · CWE-255 | Высокая7,5 | — | 2,9 % | 20 февр. 2009 г. |
31Наблюдать | CVE-2008-6232Proof of concept | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) apreprojects · pre shopping mall · CWE-255 | Высокая7,5 | — | 2,9 % | 20 февр. 2009 г. |
31Наблюдать | CVE-2008-6716Proof of concept | homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to hpreprojects · pre ads portal · CWE-287 | Высокая7,5 | — | 2,5 % | 13 апр. 2009 г. |
31Наблюдать | CVE-2008-2917Proof of concept | SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_preprojects · e-smart cart · CWE-89 | Высокая7,5 | — | 1,7 % | 30 июн. 2008 г. |
30Наблюдать | CVE-2010-0954Эксплойта нет | SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commpreprojects · pre e-learning portal · CWE-89 | Высокая7,5 | — | 1,3 % | 10 мар. 2010 г. |
30Наблюдать | CVE-2012-5334Proof of concept | SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid preprojects · pre printing press · CWE-89 | Высокая7,5 | — | 1,3 % | 8 окт. 2012 г. |
30Наблюдать | CVE-2012-5333Proof of concept | SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameterpreprojects · pre printing press · CWE-89 | Высокая7,5 | — | 1,2 % | 8 окт. 2012 г. |
30Наблюдать | CVE-2010-1370Эксплойта нет | SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre classified listings asp · CWE-89 | Высокая7,5 | — | 1,1 % | 13 апр. 2010 г. |
30Наблюдать | CVE-2011-5139Proof of concept | SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via preprojects · business cards designer · CWE-89 | Высокая7,5 | — | 1,1 % | 31 авг. 2012 г. |
30Наблюдать | CVE-2008-2915Proof of concept | Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to executpreprojects · pre job board · CWE-89 | Высокая7,5 | — | 1,0 % | 30 июн. 2008 г. |
30Наблюдать | CVE-2008-6230Proof of concept | SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre podcast portal · CWE-89 | Высокая7,5 | — | 1,0 % | 20 февр. 2009 г. |
30Наблюдать | CVE-2008-2914Proof of concept | SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arpreprojects · php jobwebsite pro · CWE-89 | Высокая7,5 | — | 1,0 % | 30 июн. 2008 г. |
30Наблюдать | CVE-2008-6887Proof of concept | SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre classified listings · CWE-89 | Высокая7,5 | — | 1,0 % | 3 авг. 2009 г. |
30Наблюдать | CVE-2010-4776Proof of concept | SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary preprojects · pre online tests generator · CWE-89 | Высокая7,5 | — | 1,0 % | 23 мар. 2011 г. |
30Наблюдать | CVE-2008-6796Proof of concept | SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL cpreprojects · pre real estate listings · CWE-89 | Высокая7,5 | — | 1,0 % | 7 мая 2009 г. |
30Наблюдать | CVE-2010-1369Proof of concept | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the epreprojects · pre classified listings asp · CWE-89 | Высокая7,5 | — | 1,0 % | 13 апр. 2010 г. |
30Наблюдать | CVE-2008-2114Proof of concept | SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the spreprojects · pre shopping mall · CWE-89 | Высокая7,5 | — | 1,0 % | 8 мая 2008 г. |
30Наблюдать | CVE-2008-4177Proof of concept | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c papreprojects · pre real estate listings · CWE-89 | Высокая7,5 | — | 1,0 % | 23 сент. 2008 г. |
30Наблюдать | CVE-2008-5977Proof of concept | SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the preprojects · php jobwebsite pro · CWE-89 | Высокая7,5 | — | 1,0 % | 26 янв. 2009 г. |
30Наблюдать | CVE-2008-6798Proof of concept | Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQLpreprojects · pre real estate listings · CWE-89 | Высокая7,5 | — | 1,0 % | 7 мая 2009 г. |
27Наблюдать | CVE-2008-7052Proof of concept | Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute preprojects · pre real estate listings · CWE-20 | Средняя6,5 | — | 3,3 % | 24 авг. 2009 г. |
27Наблюдать | CVE-2008-2916Proof of concept | Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execupreprojects · pre ads portal · CWE-89 | Средняя6,8 | — | 1,1 % | 30 июн. 2008 г. |
20Наблюдать | CVE-2008-6053Эксплойта нет | PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers preprojects · pre resume submitter · CWE-264 | Средняя5,0 | — | 1,3 % | 4 февр. 2009 г. |
20Наблюдать | CVE-2008-6052Эксплойта нет | PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackerspreprojects · pre e-learning portal · CWE-264 | Средняя5,0 | — | 1,3 % | 4 февр. 2009 г. |
20Наблюдать | CVE-2008-6055Эксплойта нет | PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to preprojects · pre classified listings · CWE-264 | Средняя5,0 | — | 1,1 % | 4 февр. 2009 г. |
- CVE-2008-623131Наблюдать
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %preprojects · pre classified listings20 февр. 2009 г.
- CVE-2008-623231Наблюдать
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) a
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %preprojects · pre shopping mall20 февр. 2009 г.
- CVE-2008-671631Наблюдать
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to h
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %preprojects · pre ads portal13 апр. 2009 г.
- CVE-2008-291731Наблюдать
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %preprojects · e-smart cart30 июн. 2008 г.
- CVE-2010-095430Наблюдать
SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL comm
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %preprojects · pre e-learning portal10 мар. 2010 г.
- CVE-2012-533430Наблюдать
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre printing press8 окт. 2012 г.
- CVE-2012-533330Наблюдать
SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre printing press8 окт. 2012 г.
- CVE-2010-137030Наблюдать
SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %preprojects · pre classified listings asp13 апр. 2010 г.
- CVE-2011-513930Наблюдать
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · business cards designer31 авг. 2012 г.
- CVE-2008-291530Наблюдать
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execut
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre job board30 июн. 2008 г.
- CVE-2008-623030Наблюдать
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre podcast portal20 февр. 2009 г.
- CVE-2008-291430Наблюдать
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute ar
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · php jobwebsite pro30 июн. 2008 г.
- CVE-2008-688730Наблюдать
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre classified listings3 авг. 2009 г.
- CVE-2010-477630Наблюдать
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre online tests generator23 мар. 2011 г.
- CVE-2008-679630Наблюдать
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre real estate listings7 мая 2009 г.
- CVE-2010-136930Наблюдать
SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the e
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre classified listings asp13 апр. 2010 г.
- CVE-2008-211430Наблюдать
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the s
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre shopping mall8 мая 2008 г.
- CVE-2008-417730Наблюдать
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre real estate listings23 сент. 2008 г.
- CVE-2008-597730Наблюдать
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · php jobwebsite pro26 янв. 2009 г.
- CVE-2008-679830Наблюдать
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %preprojects · pre real estate listings7 мая 2009 г.
- CVE-2008-705227Наблюдать
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute
СредняяCVSS 6,5Proof of conceptEPSS 3 %preprojects · pre real estate listings24 авг. 2009 г.
- CVE-2008-291627Наблюдать
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execu
СредняяCVSS 6,8Proof of conceptEPSS 1 %preprojects · pre ads portal30 июн. 2008 г.
- CVE-2008-605320Наблюдать
PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 1 %preprojects · pre resume submitter4 февр. 2009 г.
- CVE-2008-605220Наблюдать
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 1 %preprojects · pre e-learning portal4 февр. 2009 г.
- CVE-2008-605520Наблюдать
PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to
СредняяCVSS 5,0Эксплойта нетEPSS 1 %preprojects · pre classified listings4 февр. 2009 г.