Записи sir
42 опубликованных записей вендора sir.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 4,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-178 Improper Handling of Case Sensitivity1
- CWE-707 Improper Neutralization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
42 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-18662Proof of concept | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.sir · gnuboard · CWE-89 | Критическая9,8 | — | 5,4 % | 24 июн. 2021 г. |
40В плане | CVE-2005-0269Эксплойта нет | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attacsir · gnuboard · CWE-178 | Критическая9,8 | — | 2,6 % | 2 мая 2005 г. |
36Наблюдать | CVE-2022-1252Эксплойта нет | Use of a Broken or Risky Cryptographic Algorithm in gnuboard/gnuboard5sir · gnuboard · CWE-327 | Критическая9,1 | — | 0,5 % | 11 апр. 2022 г. |
35Наблюдать | CVE-2024-41475Эксплойта нет | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.sir · gnuboard · CWE-346 | Высокая8,8 | — | 0,3 % | 12 авг. 2024 г. |
31Наблюдать | CVE-2004-1403Эксплойта нет | PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by msir · gnuboard | Высокая7,5 | — | 1,7 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2011-4066Proof of concept | SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the sir · gnuboard · CWE-89 | Высокая7,5 | — | 1,6 % | 4 нояб. 2011 г. |
30Наблюдать | CVE-2022-44216Эксплойта нет | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions.sir · gnuboard · CWE-306 | Высокая7,5 | — | 0,7 % | 20 февр. 2023 г. |
28Наблюдать | CVE-2009-0290Proof of concept | Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local filessir · gnuboard · CWE-22 | Средняя6,8 | — | 3,3 % | 27 янв. 2009 г. |
27Наблюдать | CVE-2014-2339Proof of concept | Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to exesir · gnuboard · CWE-89 | Средняя6,5 | — | 2,0 % | 19 мар. 2014 г. |
26Наблюдать | CVE-2025-61464Эксплойта нет | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.sir · gnuboard · CWE-89 | Средняя6,5 | — | 0,2 % | 23 окт. 2025 г. |
24Наблюдать | CVE-2018-18676Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parametersir · gnuboard · CWE-79 | Средняя6,1 | — | 1,6 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18671Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parametersir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-15585Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web scripsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 27 мар. 2019 г. |
24Наблюдать | CVE-2018-18672Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka tsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18669Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka sir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18675Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parametesir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18673Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/mensir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18670Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,5 % | 23 июл. 2019 г. |
24Наблюдать | CVE-2018-18668Эксплойта нет | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, akasir · gnuboard · CWE-79 | Средняя6,1 | — | 1,4 % | 26 авг. 2019 г. |
24Наблюдать | CVE-2018-18674Эксплойта нет | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka tsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,2 % | 7 нояб. 2019 г. |
24Наблюдать | CVE-2020-18661Эксплойта нет | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.sir · gnuboard · CWE-79 | Средняя6,1 | — | 1,1 % | 24 июн. 2021 г. |
24Наблюдать | CVE-2018-18678Эксплойта нет | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" pasir · gnuboard · CWE-79 | Средняя6,1 | — | 1,1 % | 30 окт. 2019 г. |
24Наблюдать | CVE-2018-15582Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1sir · gnuboard · CWE-79 | Средняя6,1 | — | 1,1 % | 26 апр. 2019 г. |
24Наблюдать | CVE-2018-15583Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web scripsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,1 % | 25 мар. 2019 г. |
24Наблюдать | CVE-2018-15580Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrarsir · gnuboard · CWE-79 | Средняя6,1 | — | 1,1 % | 26 апр. 2019 г. |
- CVE-2020-1866241В плане
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %sir · gnuboard24 июн. 2021 г.
- CVE-2005-026940В плане
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sir · gnuboard2 мая 2005 г.
- CVE-2022-125236Наблюдать
Use of a Broken or Risky Cryptographic Algorithm in gnuboard/gnuboard5
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sir · gnuboard11 апр. 2022 г.
- CVE-2024-4147535Наблюдать
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sir · gnuboard12 авг. 2024 г.
- CVE-2004-140331Наблюдать
PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by m
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sir · gnuboard31 дек. 2004 г.
- CVE-2011-406630Наблюдать
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %sir · gnuboard4 нояб. 2011 г.
- CVE-2022-4421630Наблюдать
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sir · gnuboard20 февр. 2023 г.
- CVE-2009-029028Наблюдать
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files
СредняяCVSS 6,8Proof of conceptEPSS 3 %sir · gnuboard27 янв. 2009 г.
- CVE-2014-233927Наблюдать
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to exe
СредняяCVSS 6,5Proof of conceptEPSS 2 %sir · gnuboard19 мар. 2014 г.
- CVE-2025-6146426Наблюдать
gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sir · gnuboard23 окт. 2025 г.
- CVE-2018-1867624Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1867124Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1558524Наблюдать
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web scrip
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard27 мар. 2019 г.
- CVE-2018-1867224Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka t
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1866924Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1867524Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" paramete
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1867324Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/men
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1867024Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the ad
СредняяCVSS 6,1Эксплойта нетEPSS 2 %sir · gnuboard23 июл. 2019 г.
- CVE-2018-1866824Наблюдать
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard26 авг. 2019 г.
- CVE-2018-1867424Наблюдать
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka t
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard7 нояб. 2019 г.
- CVE-2020-1866124Наблюдать
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard24 июн. 2021 г.
- CVE-2018-1867824Наблюдать
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" pa
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard30 окт. 2019 г.
- CVE-2018-1558224Наблюдать
Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard26 апр. 2019 г.
- CVE-2018-1558324Наблюдать
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web scrip
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard25 мар. 2019 г.
- CVE-2018-1558024Наблюдать
Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrar
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sir · gnuboard26 апр. 2019 г.