Записи upoint
4 опубликованных записей вендора upoint.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
28Наблюдать | CVE-2006-1278Proof of concept | SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1upoint · \@1 file store · CWE-89 | Средняя6,8 | — | 3,7 % | 19 мар. 2006 г. |
23Наблюдать | CVE-2006-1277Эксплойта нет | Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script orupoint · at1 file store | Средняя5,8 | — | 1,4 % | 19 мар. 2006 г. |
20Наблюдать | CVE-2006-1437Эксплойта нет | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attupoint · at1 event publisher | Средняя5,0 | — | 1,4 % | 15 апр. 2006 г. |
17Наблюдать | CVE-2006-1436Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTupoint · at1 event publisher | Средняя4,3 | — | 1,2 % | 15 апр. 2006 г. |
- CVE-2006-127828Наблюдать
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1
СредняяCVSS 6,8Proof of conceptEPSS 4 %upoint · \@1 file store19 мар. 2006 г.
- CVE-2006-127723Наблюдать
Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or
СредняяCVSS 5,8Эксплойта нетEPSS 1 %upoint · at1 file store19 мар. 2006 г.
- CVE-2006-143720Наблюдать
UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote att
СредняяCVSS 5,0Эксплойта нетEPSS 1 %upoint · at1 event publisher15 апр. 2006 г.
- CVE-2006-143617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Эксплойта нетEPSS 1 %upoint · at1 event publisher15 апр. 2006 г.