Записи scriptsez
23 опубликованных записей вендора scriptsez.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2007-0518Proof of concept | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allowscriptsez · smart php subscriber | Высокая7,5 | — | 2,5 % | 25 янв. 2007 г. |
31Наблюдать | CVE-2009-4683Proof of concept | Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via direscriptsez · good\/bad vote · CWE-22 | Высокая7,5 | — | 2,4 % | 10 мар. 2010 г. |
30Наблюдать | CVE-2007-0517Эксплойта нет | Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackescriptsez · random php quote | Высокая7,5 | — | 1,5 % | 25 янв. 2007 г. |
30Наблюдать | CVE-2012-0983Proof of concept | SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a viscriptsez · ez album · CWE-89 | Высокая7,5 | — | 1,0 % | 2 февр. 2012 г. |
27Наблюдать | CVE-2009-4385Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the auscriptsez · ez poll hoster · CWE-352 | Средняя6,8 | — | 1,0 % | 22 дек. 2009 г. |
27Наблюдать | CVE-2009-4826Proof of concept | Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack thscriptsez · mini hosting panel · CWE-352 | Средняя6,8 | — | 0,9 % | 27 апр. 2010 г. |
21Наблюдать | CVE-2008-6089Proof of concept | Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a ..scriptsez · easy image downloader · CWE-22 | Средняя5,0 | — | 3,1 % | 6 февр. 2009 г. |
21Наблюдать | CVE-2008-6112Proof of concept | Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a ..scriptsez · ez ringtone manager · CWE-22 | Средняя5,0 | — | 3,0 % | 11 февр. 2009 г. |
21Наблюдать | CVE-2008-5218Proof of concept | ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cscriptsez · freeze greetings · CWE-264 | Средняя5,0 | — | 2,7 % | 25 нояб. 2008 г. |
18Наблюдать | CVE-2009-3601Proof of concept | Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script scriptsez · ultimate poll · CWE-79 | Средняя4,3 | — | 3,0 % | 8 окт. 2009 г. |
18Наблюдать | CVE-2008-2116Proof of concept | Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local scriptsez · power editor · CWE-22 | Средняя4,4 | — | 2,5 % | 8 мая 2008 г. |
18Наблюдать | CVE-2008-6090Proof of concept | Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via ascriptsez · mini hosting panel · CWE-22 | Средняя4,3 | — | 2,3 % | 6 февр. 2009 г. |
18Наблюдать | CVE-2006-3004Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML viascriptsez · ez ringtone manager | Средняя4,3 | — | 2,1 % | 12 июн. 2006 г. |
17Наблюдать | CVE-2009-2551Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web scriptscriptsez · easy image downloader · CWE-79 | Средняя4,3 | — | 1,5 % | 20 июл. 2009 г. |
17Наблюдать | CVE-2009-4366Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTMscriptsez · ez blog · CWE-79 | Средняя4,3 | — | 1,5 % | 21 дек. 2009 г. |
17Наблюдать | CVE-2008-2115Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrascriptsez · power editor · CWE-79 | Средняя4,3 | — | 1,5 % | 8 мая 2008 г. |
17Наблюдать | CVE-2009-4384Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web scrscriptsez · ez poll hoster · CWE-79 | Средняя4,3 | — | 1,5 % | 22 дек. 2009 г. |
17Наблюдать | CVE-2009-4364Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML viscriptsez · ez blog · CWE-79 | Средняя4,3 | — | 1,5 % | 21 дек. 2009 г. |
17Наблюдать | CVE-2009-4682Proof of concept | Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via thescriptsez · good\/bad vote · CWE-79 | Средняя4,3 | — | 1,4 % | 10 мар. 2010 г. |
17Наблюдать | CVE-2006-2232Эксплойта нет | Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTMLscriptsez · cute guestbook | Средняя4,3 | — | 1,2 % | 5 мая 2006 г. |
17Наблюдать | CVE-2009-4317Эксплойта нет | Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML viscriptsez · ez cart · CWE-79 | Средняя4,3 | — | 1,1 % | 14 дек. 2009 г. |
17Наблюдать | CVE-2009-0762Эксплойта нет | Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the scriptsez · ez php comment · CWE-79 | Средняя4,3 | — | 1,0 % | 6 мар. 2009 г. |
17Наблюдать | CVE-2009-4365Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authenscriptsez · ez blog · CWE-352 | Средняя4,3 | — | 0,9 % | 21 дек. 2009 г. |
- CVE-2007-051831Наблюдать
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allow
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %scriptsez · smart php subscriber25 янв. 2007 г.
- CVE-2009-468331Наблюдать
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via dire
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %scriptsez · good\/bad vote10 мар. 2010 г.
- CVE-2007-051730Наблюдать
Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attacke
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %scriptsez · random php quote25 янв. 2007 г.
- CVE-2012-098330Наблюдать
SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %scriptsez · ez album2 февр. 2012 г.
- CVE-2009-438527Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the au
СредняяCVSS 6,8Proof of conceptEPSS 1 %scriptsez · ez poll hoster22 дек. 2009 г.
- CVE-2009-482627Наблюдать
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack th
СредняяCVSS 6,8Proof of conceptEPSS 1 %scriptsez · mini hosting panel27 апр. 2010 г.
- CVE-2008-608921Наблюдать
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 3 %scriptsez · easy image downloader6 февр. 2009 г.
- CVE-2008-611221Наблюдать
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 3 %scriptsez · ez ringtone manager11 февр. 2009 г.
- CVE-2008-521821Наблюдать
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain c
СредняяCVSS 5,0Proof of conceptEPSS 3 %scriptsez · freeze greetings25 нояб. 2008 г.
- CVE-2009-360118Наблюдать
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 3 %scriptsez · ultimate poll8 окт. 2009 г.
- CVE-2008-211618Наблюдать
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local
СредняяCVSS 4,4Proof of conceptEPSS 3 %scriptsez · power editor8 мая 2008 г.
- CVE-2008-609018Наблюдать
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a
СредняяCVSS 4,3Proof of conceptEPSS 2 %scriptsez · mini hosting panel6 февр. 2009 г.
- CVE-2006-300418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Эксплойта нетEPSS 2 %scriptsez · ez ringtone manager12 июн. 2006 г.
- CVE-2009-255117Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 2 %scriptsez · easy image downloader20 июл. 2009 г.
- CVE-2009-436617Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog 1.0 allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Proof of conceptEPSS 2 %scriptsez · ez blog21 дек. 2009 г.
- CVE-2008-211517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitra
СредняяCVSS 4,3Proof of conceptEPSS 1 %scriptsez · power editor8 мая 2008 г.
- CVE-2009-438417Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web scr
СредняяCVSS 4,3Proof of conceptEPSS 1 %scriptsez · ez poll hoster22 дек. 2009 г.
- CVE-2009-436417Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Blog allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Proof of conceptEPSS 1 %scriptsez · ez blog21 дек. 2009 г.
- CVE-2009-468217Наблюдать
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 1 %scriptsez · good\/bad vote10 мар. 2010 г.
- CVE-2006-223217Наблюдать
Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 1 %scriptsez · cute guestbook5 мая 2006 г.
- CVE-2009-431717Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %scriptsez · ez cart14 дек. 2009 г.
- CVE-2009-076217Наблюдать
Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Эксплойта нетEPSS 1 %scriptsez · ez php comment6 мар. 2009 г.
- CVE-2009-436517Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authen
СредняяCVSS 4,3Proof of conceptEPSS 1 %scriptsez · ez blog21 дек. 2009 г.