Записи scriptphp
9 опубликованных записей вендора scriptphp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2006-6478Proof of concept | Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id paramescriptphp · annoncescripthp | Высокая7,5 | — | 10,6 % | 11 дек. 2006 г. |
30Наблюдать | CVE-2006-6521Proof of concept | SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa scriptphp · messageriescripthp | Высокая7,5 | — | 1,1 % | 13 дек. 2006 г. |
30Наблюдать | CVE-2006-6519Proof of concept | SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.scriptphp · pronews | Высокая7,5 | — | 1,1 % | 13 дек. 2006 г. |
28Наблюдать | CVE-2006-6520Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML scriptphp · messageriescripthp | Средняя6,8 | — | 2,1 % | 13 дек. 2006 г. |
28Наблюдать | CVE-2006-6479Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML viascriptphp · annoncescripthp | Средняя6,8 | — | 2,1 % | 11 дек. 2006 г. |
28Наблюдать | CVE-2006-6518Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1)scriptphp · pronews | Средняя6,8 | — | 1,9 % | 13 дек. 2006 г. |
25Наблюдать | CVE-2006-6580Эксплойта нет | admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delscriptphp · pronews | Средняя6,4 | — | 1,2 % | 15 дек. 2006 г. |
20Наблюдать | CVE-2006-6480Эксплойта нет | admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parametescriptphp · annoncescripthp | Средняя5,0 | — | 1,3 % | 11 дек. 2006 г. |
17Наблюдать | CVE-2008-2280Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web scriscriptphp · picengine · CWE-79 | Средняя4,3 | — | 1,1 % | 16 мая 2008 г. |
- CVE-2006-647833Наблюдать
Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parame
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %scriptphp · annoncescripthp11 дек. 2006 г.
- CVE-2006-652130Наблюдать
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %scriptphp · messageriescripthp13 дек. 2006 г.
- CVE-2006-651930Наблюдать
SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %scriptphp · pronews13 дек. 2006 г.
- CVE-2006-652028Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,8Proof of conceptEPSS 2 %scriptphp · messageriescripthp13 дек. 2006 г.
- CVE-2006-647928Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 6,8Proof of conceptEPSS 2 %scriptphp · annoncescripthp11 дек. 2006 г.
- CVE-2006-651828Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1)
СредняяCVSS 6,8Proof of conceptEPSS 2 %scriptphp · pronews13 дек. 2006 г.
- CVE-2006-658025Наблюдать
admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or del
СредняяCVSS 6,4Эксплойта нетEPSS 1 %scriptphp · pronews15 дек. 2006 г.
- CVE-2006-648020Наблюдать
admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre paramete
СредняяCVSS 5,0Эксплойта нетEPSS 1 %scriptphp · annoncescripthp11 дек. 2006 г.
- CVE-2008-228017Наблюдать
Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web scri
СредняяCVSS 4,3Эксплойта нетEPSS 1 %scriptphp · picengine16 мая 2008 г.