Записи simplog
14 опубликованных записей вендора simplog.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2006-1776Proof of concept | PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbsimplog · simplog | Высокая7,5 | — | 12,7 % | 13 апр. 2006 г. |
33Наблюдать | CVE-2006-1777Proof of concept | Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execusimplog · simplog | Высокая7,5 | — | 9,8 % | 13 апр. 2006 г. |
31Наблюдать | CVE-2006-1778Proof of concept | Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commandssimplog · simplog | Высокая7,5 | — | 4,3 % | 13 апр. 2006 г. |
30Наблюдать | CVE-2005-3076Эксплойта нет | Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, simplog · simplog | Высокая7,5 | — | 1,5 % | 27 сент. 2005 г. |
30Наблюдать | CVE-2006-5398Proof of concept | SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands via the cid parametsimplog · simplog | Высокая7,5 | — | 1,3 % | 18 окт. 2006 г. |
29Наблюдать | CVE-2006-1779Proof of concept | Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrasimplog · simplog | Средняя6,8 | — | 5,8 % | 13 апр. 2006 г. |
29Наблюдать | CVE-2009-4092Proof of concept | Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the simplog · simplog · CWE-352 | Средняя6,8 | — | 5,3 % | 29 нояб. 2009 г. |
27Наблюдать | CVE-2006-4058Эксплойта нет | Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script simplog · simplog | Средняя6,8 | — | 1,5 % | 9 авг. 2006 г. |
26Наблюдать | CVE-2006-1073Proof of concept | Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .tsimplog · simplog | Средняя6,4 | — | 3,1 % | 7 мар. 2006 г. |
26Наблюдать | CVE-2006-2029Proof of concept | Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commandssimplog · simplog | Средняя6,4 | — | 2,3 % | 25 апр. 2006 г. |
24Наблюдать | CVE-2006-2028Proof of concept | Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbsimplog · simplog | Средняя5,8 | — | 2,7 % | 25 апр. 2006 г. |
22Наблюдать | CVE-2009-4091Proof of concept | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete cosimplog · simplog · CWE-264 | Средняя5,0 | — | 6,4 % | 29 нояб. 2009 г. |
18Наблюдать | CVE-2009-4093Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to injesimplog · simplog · CWE-79 | Средняя4,3 | — | 3,9 % | 29 нояб. 2009 г. |
17Наблюдать | CVE-2006-1072Эксплойта нет | Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTMsimplog · simplog | Средняя4,3 | — | 1,2 % | 7 мар. 2006 г. |
- CVE-2006-177634Наблюдать
PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arb
ВысокаяCVSS 7,5Proof of conceptEPSS 13 %simplog · simplog13 апр. 2006 г.
- CVE-2006-177733Наблюдать
Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execu
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %simplog · simplog13 апр. 2006 г.
- CVE-2006-177831Наблюдать
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %simplog · simplog13 апр. 2006 г.
- CVE-2005-307630Наблюдать
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplog · simplog27 сент. 2005 г.
- CVE-2006-539830Наблюдать
SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands via the cid paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %simplog · simplog18 окт. 2006 г.
- CVE-2006-177929Наблюдать
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitra
СредняяCVSS 6,8Proof of conceptEPSS 6 %simplog · simplog13 апр. 2006 г.
- CVE-2009-409229Наблюдать
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the
СредняяCVSS 6,8Proof of conceptEPSS 5 %simplog · simplog29 нояб. 2009 г.
- CVE-2006-405827Наблюдать
Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script
СредняяCVSS 6,8Эксплойта нетEPSS 1 %simplog · simplog9 авг. 2006 г.
- CVE-2006-107326Наблюдать
Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .t
СредняяCVSS 6,4Proof of conceptEPSS 3 %simplog · simplog7 мар. 2006 г.
- CVE-2006-202926Наблюдать
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands
СредняяCVSS 6,4Proof of conceptEPSS 2 %simplog · simplog25 апр. 2006 г.
- CVE-2006-202824Наблюдать
Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arb
СредняяCVSS 5,8Proof of conceptEPSS 3 %simplog · simplog25 апр. 2006 г.
- CVE-2009-409122Наблюдать
comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete co
СредняяCVSS 5,0Proof of conceptEPSS 6 %simplog · simplog29 нояб. 2009 г.
- CVE-2009-409318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inje
СредняяCVSS 4,3Proof of conceptEPSS 4 %simplog · simplog29 нояб. 2009 г.
- CVE-2006-107217Наблюдать
Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTM
СредняяCVSS 4,3Эксплойта нетEPSS 1 %simplog · simplog7 мар. 2006 г.