Записи uapplication
13 опубликованных записей вендора uapplication.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2005-1427Эксплойта нет | Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information viuapplication · uphotogallery | Высокая7,5 | — | 1,7 % | 3 мая 2005 г. |
30Наблюдать | CVE-2005-1428Эксплойта нет | edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.uapplication · uphotogallery | Высокая7,5 | — | 1,5 % | 3 мая 2005 г. |
30Наблюдать | CVE-2006-6247Proof of concept | Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ciuapplication · uphotogallery | Высокая7,5 | — | 1,2 % | 4 дек. 2006 г. |
30Наблюдать | CVE-2007-0799Эксплойта нет | SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vuapplication · ublog | Высокая7,5 | — | 1,2 % | 6 февр. 2007 г. |
23Наблюдать | CVE-2006-2246Эксплойта нет | Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via textuapplication · ublog | Средняя5,8 | — | 1,5 % | 9 мая 2006 г. |
20Наблюдать | CVE-2005-1425Эксплойта нет | Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers uapplication · uguestbook · CWE-264 | Средняя5,0 | — | 1,5 % | 3 мая 2005 г. |
20Наблюдать | CVE-2005-1426Эксплойта нет | Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers touapplication · ublog · CWE-264 | Средняя5,0 | — | 1,5 % | 3 мая 2005 г. |
20Наблюдать | CVE-2005-0938Эксплойта нет | Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passworuapplication · ublog reload | Средняя5,0 | — | 1,4 % | 2 мая 2005 г. |
18Наблюдать | CVE-2005-2010Proof of concept | Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTuapplication · ublog reload | Средняя4,3 | — | 3,6 % | 20 июн. 2005 г. |
18Наблюдать | CVE-2007-0798Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via uapplication · ublog reload | Средняя4,3 | — | 2,0 % | 6 февр. 2007 г. |
18Наблюдать | CVE-2005-0925Proof of concept | Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web scruapplication · ublog reload | Средняя4,3 | — | 2,0 % | 2 мая 2005 г. |
18Наблюдать | CVE-2006-3023Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers tuapplication · uphotogallery | Средняя4,3 | — | 1,8 % | 15 июн. 2006 г. |
17Наблюдать | CVE-2007-0815Эксплойта нет | Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators uapplication · uphotogallery | Средняя4,3 | — | 1,1 % | 7 февр. 2007 г. |
- CVE-2005-142731Наблюдать
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %uapplication · uphotogallery3 мая 2005 г.
- CVE-2005-142830Наблюдать
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %uapplication · uphotogallery3 мая 2005 г.
- CVE-2006-624730Наблюдать
Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %uapplication · uphotogallery4 дек. 2006 г.
- CVE-2007-079930Наблюдать
SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified v
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %uapplication · ublog6 февр. 2007 г.
- CVE-2006-224623Наблюдать
Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text
СредняяCVSS 5,8Эксплойта нетEPSS 1 %uapplication · ublog9 мая 2006 г.
- CVE-2005-142520Наблюдать
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 2 %uapplication · uguestbook3 мая 2005 г.
- CVE-2005-142620Наблюдать
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to
СредняяCVSS 5,0Эксплойта нетEPSS 2 %uapplication · ublog3 мая 2005 г.
- CVE-2005-093820Наблюдать
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwor
СредняяCVSS 5,0Эксплойта нетEPSS 1 %uapplication · ublog reload2 мая 2005 г.
- CVE-2005-201018Наблюдать
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Proof of conceptEPSS 4 %uapplication · ublog reload20 июн. 2005 г.
- CVE-2007-079818Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Эксплойта нетEPSS 2 %uapplication · ublog reload6 февр. 2007 г.
- CVE-2005-092518Наблюдать
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web scr
СредняяCVSS 4,3Proof of conceptEPSS 2 %uapplication · ublog reload2 мая 2005 г.
- CVE-2006-302318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers t
СредняяCVSS 4,3Эксплойта нетEPSS 2 %uapplication · uphotogallery15 июн. 2006 г.
- CVE-2007-081517Наблюдать
Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators
СредняяCVSS 4,3Эксплойта нетEPSS 1 %uapplication · uphotogallery7 февр. 2007 г.