Записи w2b
14 опубликованных записей вендора w2b.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2007-3175Эксплойта нет | Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft paraw2b · online banking | Высокая7,5 | — | 16,7 % | 11 июн. 2007 г. |
32Наблюдать | CVE-2008-6921Proof of concept | Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file w2b · phpadboard · CWE-264 | Высокая7,5 | — | 5,1 % | 10 авг. 2009 г. |
32Наблюдать | CVE-2008-6920Proof of concept | Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a filw2b · phpemployment · CWE-264 | Высокая7,5 | — | 5,1 % | 10 авг. 2009 г. |
31Наблюдать | CVE-2008-3179Proof of concept | Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to inclw2b · phpdatingclub · CWE-22 | Высокая7,5 | — | 2,8 % | 15 июл. 2008 г. |
31Наблюдать | CVE-2008-1893Proof of concept | PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL iw2b · online banking · CWE-94 | Высокая7,5 | — | 2,3 % | 18 апр. 2008 г. |
30Наблюдать | CVE-2005-4088Эксплойта нет | SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent andw2b · phpforumpro | Высокая7,5 | — | 1,2 % | 8 дек. 2005 г. |
30Наблюдать | CVE-2008-1844Proof of concept | SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parametw2b · phphotresources · CWE-89 | Высокая7,5 | — | 1,2 % | 16 апр. 2008 г. |
30Наблюдать | CVE-2008-1843Proof of concept | SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via w2b · dating club · CWE-89 | Высокая7,5 | — | 1,2 % | 16 апр. 2008 г. |
30Наблюдать | CVE-2009-2179Proof of concept | SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] w2b · phpdatingclub · CWE-89 | Высокая7,5 | — | 1,0 % | 23 июн. 2009 г. |
28Наблюдать | CVE-2008-6849Proof of concept | Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading w2b · phpgreetcards · CWE-94 | Средняя6,8 | — | 2,3 % | 7 июл. 2009 г. |
18Наблюдать | CVE-2008-6848Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML viw2b · phpgreetcards · CWE-79 | Средняя4,3 | — | 1,8 % | 7 июл. 2009 г. |
17Наблюдать | CVE-2009-2178Proof of concept | Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML w2b · phpdatingclub · CWE-79 | Средняя4,3 | — | 1,2 % | 23 июн. 2009 г. |
17Наблюдать | CVE-2007-3174Эксплойта нет | Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML viw2b · online banking | Средняя4,3 | — | 1,0 % | 11 июн. 2007 г. |
11Наблюдать | CVE-2006-1980Proof of concept | Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) quw2b · online banking | Низкая2,6 | — | 2,0 % | 21 апр. 2006 г. |
- CVE-2007-317535Наблюдать
Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft para
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %w2b · online banking11 июн. 2007 г.
- CVE-2008-692132Наблюдать
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %w2b · phpadboard10 авг. 2009 г.
- CVE-2008-692032Наблюдать
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a fil
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %w2b · phpemployment10 авг. 2009 г.
- CVE-2008-317931Наблюдать
Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to incl
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %w2b · phpdatingclub15 июл. 2008 г.
- CVE-2008-189331Наблюдать
PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL i
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %w2b · online banking18 апр. 2008 г.
- CVE-2005-408830Наблюдать
SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %w2b · phpforumpro8 дек. 2005 г.
- CVE-2008-184430Наблюдать
SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %w2b · phphotresources16 апр. 2008 г.
- CVE-2008-184330Наблюдать
SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %w2b · dating club16 апр. 2008 г.
- CVE-2009-217930Наблюдать
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day]
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %w2b · phpdatingclub23 июн. 2009 г.
- CVE-2008-684928Наблюдать
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading
СредняяCVSS 6,8Proof of conceptEPSS 2 %w2b · phpgreetcards7 июл. 2009 г.
- CVE-2008-684818Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Proof of conceptEPSS 2 %w2b · phpgreetcards7 июл. 2009 г.
- CVE-2009-217817Наблюдать
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 1 %w2b · phpdatingclub23 июн. 2009 г.
- CVE-2007-317417Наблюдать
Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %w2b · online banking11 июн. 2007 г.
- CVE-2006-198011Наблюдать
Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) qu
НизкаяCVSS 2,6Proof of conceptEPSS 2 %w2b · online banking21 апр. 2006 г.