Записи vwar
22 опубликованных записей вендора vwar.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-189 Numeric Errors1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2006-1747Proof of concept | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vvwar · virtual war | Высокая7,5 | — | 3,9 % | 12 апр. 2006 г. |
31Наблюдать | CVE-2007-4605Proof of concept | PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute avwar · virtual war · CWE-94 | Высокая7,5 | — | 2,1 % | 30 авг. 2007 г. |
31Наблюдать | CVE-2006-1636Эксплойта нет | PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP codvwar · virtual war · CWE-94 | Высокая7,5 | — | 2,1 % | 6 апр. 2006 г. |
31Наблюдать | CVE-2006-4010Proof of concept | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands viavwar · virtual war · CWE-89 | Высокая7,5 | — | 1,8 % | 7 авг. 2006 г. |
31Наблюдать | CVE-2006-3139Эксплойта нет | Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQvwar · virtual war · CWE-89 | Высокая7,5 | — | 1,8 % | 22 июн. 2006 г. |
30Наблюдать | CVE-2006-4142Proof of concept | SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQLvwar · virtual war | Высокая7,5 | — | 1,3 % | 14 авг. 2006 г. |
30Наблюдать | CVE-2006-4141Эксплойта нет | SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vivwar · virtual war | Высокая7,5 | — | 1,2 % | 14 авг. 2006 г. |
30Наблюдать | CVE-2007-2312Proof of concept | Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary Svwar · virtual war | Высокая7,5 | — | 1,2 % | 26 апр. 2007 г. |
30Наблюдать | CVE-2010-5063Proof of concept | SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via vwar · virtual war · CWE-89 | Высокая7,5 | — | 1,1 % | 8 окт. 2012 г. |
30Наблюдать | CVE-2008-0753Proof of concept | SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the montvwar · virtual war · CWE-89 | Высокая7,5 | — | 1,0 % | 13 февр. 2008 г. |
27Наблюдать | CVE-2010-5067Эксплойта нет | Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackervwar · virtual war · CWE-255 | Средняя6,8 | — | 1,3 % | 8 окт. 2012 г. |
27Наблюдать | CVE-2005-4748Эксплойта нет | PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute vwar · virtual war | Средняя6,8 | — | 1,3 % | 31 дек. 2005 г. |
21Наблюдать | CVE-2006-1503Эксплойта нет | PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackervwar · virtual war · CWE-94 | Средняя5,1 | — | 2,0 % | 29 мар. 2006 г. |
20Наблюдать | CVE-2006-2091Эксплойта нет | admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_rootvwar · virtual war | Средняя5,0 | — | 1,4 % | 29 апр. 2006 г. |
20Наблюдать | CVE-2010-5065Эксплойта нет | popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifivwar · virtual war · CWE-264 | Средняя5,0 | — | 1,4 % | 8 окт. 2012 г. |
20Наблюдать | CVE-2010-5279Эксплойта нет | article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integervwar · virtual war · CWE-189 | Средняя5,0 | — | 1,3 % | 8 окт. 2012 г. |
20Наблюдать | CVE-2011-3813Эксплойта нет | Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals tvwar · virtual war · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
18Наблюдать | CVE-2006-4009Proof of concept | Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web vwar · virtual war | Средняя4,3 | — | 1,7 % | 7 авг. 2006 г. |
17Наблюдать | CVE-2010-5066Эксплойта нет | The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to selectvwar · virtual war · CWE-310 | Средняя4,3 | — | 1,2 % | 8 окт. 2012 г. |
17Наблюдать | CVE-2006-4224Эксплойта нет | Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitraryvwar · virtual war | Средняя4,3 | — | 1,2 % | 18 авг. 2006 г. |
17Наблюдать | CVE-2007-2306Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globavwar · virtual war | Средняя4,3 | — | 1,1 % | 26 апр. 2007 г. |
17Наблюдать | CVE-2010-5064Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web scriptvwar · virtual war · CWE-79 | Средняя4,3 | — | 1,0 % | 8 окт. 2012 г. |
- CVE-2006-174731Наблюдать
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the v
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %vwar · virtual war12 апр. 2006 г.
- CVE-2007-460531Наблюдать
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %vwar · virtual war30 авг. 2007 г.
- CVE-2006-163631Наблюдать
PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP cod
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vwar · virtual war6 апр. 2006 г.
- CVE-2006-401031Наблюдать
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %vwar · virtual war7 авг. 2006 г.
- CVE-2006-313931Наблюдать
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vwar · virtual war22 июн. 2006 г.
- CVE-2006-414230Наблюдать
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %vwar · virtual war14 авг. 2006 г.
- CVE-2006-414130Наблюдать
SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vwar · virtual war14 авг. 2006 г.
- CVE-2007-231230Наблюдать
Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary S
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %vwar · virtual war26 апр. 2007 г.
- CVE-2010-506330Наблюдать
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %vwar · virtual war8 окт. 2012 г.
- CVE-2008-075330Наблюдать
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the mont
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %vwar · virtual war13 февр. 2008 г.
- CVE-2010-506727Наблюдать
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attacker
СредняяCVSS 6,8Эксплойта нетEPSS 1 %vwar · virtual war8 окт. 2012 г.
- CVE-2005-474827Наблюдать
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute
СредняяCVSS 6,8Эксплойта нетEPSS 1 %vwar · virtual war31 дек. 2005 г.
- CVE-2006-150321Наблюдать
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attacker
СредняяCVSS 5,1Эксплойта нетEPSS 2 %vwar · virtual war29 мар. 2006 г.
- CVE-2006-209120Наблюдать
admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root
СредняяCVSS 5,0Эксплойта нетEPSS 1 %vwar · virtual war29 апр. 2006 г.
- CVE-2010-506520Наблюдать
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifi
СредняяCVSS 5,0Эксплойта нетEPSS 1 %vwar · virtual war8 окт. 2012 г.
- CVE-2010-527920Наблюдать
article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer
СредняяCVSS 5,0Эксплойта нетEPSS 1 %vwar · virtual war8 окт. 2012 г.
- CVE-2011-381320Наблюдать
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals t
СредняяCVSS 5,0Эксплойта нетEPSS 1 %vwar · virtual war23 сент. 2011 г.
- CVE-2006-400918Наблюдать
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Proof of conceptEPSS 2 %vwar · virtual war7 авг. 2006 г.
- CVE-2010-506617Наблюдать
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select
СредняяCVSS 4,3Эксплойта нетEPSS 1 %vwar · virtual war8 окт. 2012 г.
- CVE-2006-422417Наблюдать
Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 1 %vwar · virtual war18 авг. 2006 г.
- CVE-2007-230617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globa
СредняяCVSS 4,3Эксплойта нетEPSS 1 %vwar · virtual war26 апр. 2007 г.
- CVE-2010-506417Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %vwar · virtual war8 окт. 2012 г.