Записи prozilla
15 опубликованных записей вендора prozilla.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 20 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2004-1120Proof of concept | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and prozilla · prozilla download accelerator | Критическая10,0 | — | 14,6 % | 10 янв. 2005 г. |
33Наблюдать | CVE-2005-0523Proof of concept | Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers iprozilla · prozilla download accelerator | Высокая7,5 | — | 9,9 % | 2 мая 2005 г. |
33Наблюдать | CVE-2005-2961Proof of concept | Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remotprozilla · prozilla download accelerator | Высокая7,5 | — | 8,6 % | 5 окт. 2005 г. |
31Наблюдать | CVE-2008-1784Proof of concept | Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3)prozilla · topsites · CWE-264 | Высокая7,5 | — | 2,5 % | 15 апр. 2008 г. |
31Наблюдать | CVE-2008-1863Proof of concept | SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL cprozilla · cheats · CWE-89 | Высокая7,5 | — | 2,1 % | 17 апр. 2008 г. |
30Наблюдать | CVE-2008-6115Proof of concept | SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id prozilla · hosting index · CWE-89 | Высокая7,5 | — | 1,1 % | 11 февр. 2009 г. |
30Наблюдать | CVE-2007-3809Proof of concept | Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id prozilla · prozilla directory script | Высокая7,5 | — | 1,0 % | 16 июл. 2007 г. |
30Наблюдать | CVE-2008-1864Proof of concept | SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the projectprozilla · prozilla freelancers · CWE-89 | Высокая7,5 | — | 1,0 % | 17 апр. 2008 г. |
30Наблюдать | CVE-2007-4258Proof of concept | SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via thprozilla · prozilla pub site directory · CWE-89 | Высокая7,5 | — | 1,0 % | 8 авг. 2007 г. |
30Наблюдать | CVE-2008-1788Proof of concept | SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commaprozilla · entertainers · CWE-89 | Высокая7,5 | — | 0,9 % | 15 апр. 2008 г. |
27Наблюдать | CVE-2007-4362Proof of concept | SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parameprozilla · webring | Средняя6,8 | — | 1,2 % | 15 авг. 2007 г. |
27Наблюдать | CVE-2008-2083Proof of concept | SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to executprozilla · hosting index · CWE-89 | Средняя6,8 | — | 1,1 % | 5 мая 2008 г. |
27Наблюдать | CVE-2008-1789Proof of concept | SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameterprozilla · forum · CWE-89 | Средняя6,8 | — | 0,9 % | 15 апр. 2008 г. |
26Наблюдать | CVE-2008-1783Proof of concept | Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/Deleprozilla · reviews · CWE-264 | Средняя6,4 | — | 2,3 % | 15 апр. 2008 г. |
23Наблюдать | CVE-2008-1785Proof of concept | delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s pprozilla · top 100 · CWE-20 | Средняя5,5 | — | 2,0 % | 15 апр. 2008 г. |
- CVE-2004-112044В плане
Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and
КритическаяCVSS 10,0Proof of conceptEPSS 15 %prozilla · prozilla download accelerator10 янв. 2005 г.
- CVE-2005-052333Наблюдать
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers i
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %prozilla · prozilla download accelerator2 мая 2005 г.
- CVE-2005-296133Наблюдать
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remot
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %prozilla · prozilla download accelerator5 окт. 2005 г.
- CVE-2008-178431Наблюдать
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3)
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %prozilla · topsites15 апр. 2008 г.
- CVE-2008-186331Наблюдать
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL c
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %prozilla · cheats17 апр. 2008 г.
- CVE-2008-611530Наблюдать
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %prozilla · hosting index11 февр. 2009 г.
- CVE-2007-380930Наблюдать
Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %prozilla · prozilla directory script16 июл. 2007 г.
- CVE-2008-186430Наблюдать
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %prozilla · prozilla freelancers17 апр. 2008 г.
- CVE-2007-425830Наблюдать
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %prozilla · prozilla pub site directory8 авг. 2007 г.
- CVE-2008-178830Наблюдать
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %prozilla · entertainers15 апр. 2008 г.
- CVE-2007-436227Наблюдать
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL commands via the cat parame
СредняяCVSS 6,8Proof of conceptEPSS 1 %prozilla · webring15 авг. 2007 г.
- CVE-2008-208327Наблюдать
SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execut
СредняяCVSS 6,8Proof of conceptEPSS 1 %prozilla · hosting index5 мая 2008 г.
- CVE-2008-178927Наблюдать
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter
СредняяCVSS 6,8Proof of conceptEPSS 1 %prozilla · forum15 апр. 2008 г.
- CVE-2008-178326Наблюдать
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/Dele
СредняяCVSS 6,4Proof of conceptEPSS 2 %prozilla · reviews15 апр. 2008 г.
- CVE-2008-178523Наблюдать
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s p
СредняяCVSS 5,5Proof of conceptEPSS 2 %prozilla · top 10015 апр. 2008 г.