Записи refbase
10 опубликованных записей вендора refbase.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2015-6008Proof of concept | install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassworrefbase · refbase · CWE-78 | Высокая7,5 | — | 4,8 % | 27 сент. 2015 г. |
31Наблюдать | CVE-2015-7381Proof of concept | Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackerefbase · refbase · CWE-94 | Высокая7,5 | — | 3,2 % | 27 сент. 2015 г. |
30Наблюдать | CVE-2015-6009Proof of concept | Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQLrefbase · refbase · CWE-89 | Высокая7,5 | — | 1,5 % | 27 сент. 2015 г. |
30Наблюдать | CVE-2015-7382Proof of concept | SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrarrefbase · refbase · CWE-89 | Высокая7,5 | — | 1,5 % | 27 сент. 2015 г. |
27Наблюдать | CVE-2015-6007Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the refbase · refbase · CWE-352 | Средняя6,8 | — | 0,7 % | 27 сент. 2015 г. |
23Наблюдать | CVE-2015-6012Эксплойта нет | Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remotrefbase · refbase | Средняя5,8 | — | 1,2 % | 27 сент. 2015 г. |
20Наблюдать | CVE-2015-6011Эксплойта нет | Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attarefbase · refbase | Средняя5,0 | — | 1,2 % | 27 сент. 2015 г. |
17Наблюдать | CVE-2015-7383Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-refbase · refbase · CWE-79 | Средняя4,3 | — | 1,2 % | 27 сент. 2015 г. |
17Наблюдать | CVE-2015-6010Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-0refbase · refbase · CWE-79 | Средняя4,3 | — | 1,2 % | 27 сент. 2015 г. |
17Наблюдать | CVE-2008-6400Эксплойта нет | Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headrefbase · refbase · CWE-79 | Средняя4,3 | — | 1,0 % | 5 мар. 2009 г. |
- CVE-2015-600831Наблюдать
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPasswor
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %refbase · refbase27 сент. 2015 г.
- CVE-2015-738131Наблюдать
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attacke
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %refbase · refbase27 сент. 2015 г.
- CVE-2015-600930Наблюдать
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %refbase · refbase27 сент. 2015 г.
- CVE-2015-738230Наблюдать
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrar
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2015-600727Наблюдать
Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the
СредняяCVSS 6,8Эксплойта нетEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2015-601223Наблюдать
Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remot
СредняяCVSS 5,8Эксплойта нетEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2015-601120Наблюдать
Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection atta
СредняяCVSS 5,0Эксплойта нетEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2015-738317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-
СредняяCVSS 4,3Эксплойта нетEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2015-601017Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-0
СредняяCVSS 4,3Эксплойта нетEPSS 1 %refbase · refbase27 сент. 2015 г.
- CVE-2008-640017Наблюдать
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the head
СредняяCVSS 4,3Эксплойта нетEPSS 1 %refbase · refbase5 мар. 2009 г.