Записи turnkeyforms
12 опубликованных записей вендора turnkeyforms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-6939Proof of concept | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adturnkeyforms · web hosting directory · CWE-287 | Высокая7,5 | — | 3,1 % | 12 авг. 2009 г. |
31Наблюдать | CVE-2008-6940Proof of concept | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attturnkeyforms · web hosting directory · CWE-264 | Высокая7,5 | — | 2,8 % | 12 авг. 2009 г. |
31Наблюдать | CVE-2008-6723Proof of concept | TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoturnkeyforms · entertainment portal · CWE-287 | Высокая7,5 | — | 2,6 % | 14 апр. 2009 г. |
31Наблюдать | CVE-2008-6302Proof of concept | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_turnkeyforms · local classifieds · CWE-264 | Высокая7,5 | — | 2,6 % | 26 февр. 2009 г. |
31Наблюдать | CVE-2008-6963Proof of concept | admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct rturnkeyforms · text link sales · CWE-264 | Высокая7,5 | — | 2,5 % | 13 авг. 2009 г. |
30Наблюдать | CVE-2008-6941Proof of concept | SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQturnkeyforms · web hosting directory · CWE-89 | Высокая7,5 | — | 1,1 % | 12 авг. 2009 г. |
30Наблюдать | CVE-2008-5486Proof of concept | SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the iturnkeyforms · text link sales · CWE-89 | Высокая7,5 | — | 1,0 % | 12 дек. 2008 г. |
30Наблюдать | CVE-2008-6350Proof of concept | SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via turnkeyforms · local classifieds · CWE-89 | Высокая7,5 | — | 1,0 % | 2 мар. 2009 г. |
30Наблюдать | CVE-2008-6349Proof of concept | SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary turnkeyforms · business survey pro · CWE-89 | Высокая7,5 | — | 1,0 % | 2 мар. 2009 г. |
17Наблюдать | CVE-2008-5487Proof of concept | Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web scriptturnkeyforms · text link sales · CWE-79 | Средняя4,3 | — | 1,6 % | 12 дек. 2008 г. |
17Наблюдать | CVE-2008-6351Proof of concept | Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web sturnkeyforms · local classifieds · CWE-79 | Средняя4,3 | — | 1,5 % | 2 мар. 2009 г. |
17Наблюдать | CVE-2009-4858Proof of concept | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web scriptturnkeyforms · yahoo-answers-clone · CWE-79 | Средняя4,3 | — | 1,3 % | 11 мая 2010 г. |
- CVE-2008-693931Наблюдать
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the ad
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %turnkeyforms · web hosting directory12 авг. 2009 г.
- CVE-2008-694031Наблюдать
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote att
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %turnkeyforms · web hosting directory12 авг. 2009 г.
- CVE-2008-672331Наблюдать
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLo
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %turnkeyforms · entertainment portal14 апр. 2009 г.
- CVE-2008-630231Наблюдать
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %turnkeyforms · local classifieds26 февр. 2009 г.
- CVE-2008-696331Наблюдать
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct r
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %turnkeyforms · text link sales13 авг. 2009 г.
- CVE-2008-694130Наблюдать
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %turnkeyforms · web hosting directory12 авг. 2009 г.
- CVE-2008-548630Наблюдать
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the i
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %turnkeyforms · text link sales12 дек. 2008 г.
- CVE-2008-635030Наблюдать
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %turnkeyforms · local classifieds2 мар. 2009 г.
- CVE-2008-634930Наблюдать
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %turnkeyforms · business survey pro2 мар. 2009 г.
- CVE-2008-548717Наблюдать
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 2 %turnkeyforms · text link sales12 дек. 2008 г.
- CVE-2008-635117Наблюдать
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web s
СредняяCVSS 4,3Proof of conceptEPSS 1 %turnkeyforms · local classifieds2 мар. 2009 г.
- CVE-2009-485817Наблюдать
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 1 %turnkeyforms · yahoo-answers-clone11 мая 2010 г.