Записи web-app.org
36 опубликованных записей вендора web-app.org.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-16 Configuration1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2005-0927Эксплойта нет | Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacweb-app.org · webapp | Критическая10,0 | — | 1,6 % | 2 мая 2005 г. |
33Наблюдать | CVE-2005-1628Proof of concept | apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharactersweb-app.org · webapp · CWE-20 | Высокая7,5 | — | 10,6 % | 17 мая 2005 г. |
31Наблюдать | CVE-2007-3242Эксплойта нет | The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allowsweb-app.net · webapp · CWE-264 | Высокая7,5 | — | 2,1 % | 14 июн. 2007 г. |
30Наблюдать | CVE-2007-1188Эксплойта нет | WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has uweb-app.org · webapp | Высокая7,5 | — | 1,5 % | 2 мар. 2007 г. |
30Наблюдать | CVE-2007-1183Эксплойта нет | WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attacweb-app.org · webapp | Высокая7,5 | — | 1,5 % | 2 мар. 2007 г. |
30Наблюдать | CVE-2007-1178Эксплойта нет | WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,web-app.org · webapp | Высокая7,5 | — | 1,4 % | 2 мар. 2007 г. |
30Наблюдать | CVE-2007-1259Эксплойта нет | Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.web-app.org · webapp | Высокая7,5 | — | 1,3 % | 3 мар. 2007 г. |
30Наблюдать | CVE-2007-3424Эксплойта нет | The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory namweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
30Наблюдать | CVE-2007-3419Эксплойта нет | The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) laweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
30Наблюдать | CVE-2007-3420Эксплойта нет | The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not cweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
30Наблюдать | CVE-2007-3421Эксплойта нет | The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
30Наблюдать | CVE-2007-3422Эксплойта нет | The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-priweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
30Наблюдать | CVE-2007-3423Эксплойта нет | cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .daweb-app.org · webapp | Высокая7,5 | — | 1,1 % | 26 июн. 2007 г. |
27Наблюдать | CVE-2007-1489Эксплойта нет | Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin accesweb-app.org · webapp · CWE-352 | Средняя6,8 | — | 0,7 % | 16 мар. 2007 г. |
26Наблюдать | CVE-2007-3418Эксплойта нет | The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction web-app.org · webapp | Средняя6,5 | — | 1,1 % | 26 июн. 2007 г. |
25Наблюдать | CVE-2007-1827Эксплойта нет | Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corruweb-app.org · webapp | Средняя6,0 | — | 1,9 % | 2 апр. 2007 г. |
25Наблюдать | CVE-2007-1182Эксплойта нет | WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.web-app.org · webapp | Средняя6,4 | — | 1,1 % | 2 мар. 2007 г. |
24Наблюдать | CVE-2007-1831Эксплойта нет | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.web-app.org · webapp | Средняя6,0 | — | 1,1 % | 2 апр. 2007 г. |
23Наблюдать | CVE-2007-1177Эксплойта нет | WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Pweb-app.org · webapp | Средняя5,8 | — | 1,1 % | 2 мар. 2007 г. |
22Наблюдать | CVE-2004-1742Proof of concept | Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..web-app.org · webapp | Средняя5,0 | — | 7,2 % | 24 авг. 2004 г. |
22Наблюдать | CVE-2007-1187Эксплойта нет | WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archiveweb-app.org · webapp | Средняя5,5 | — | 1,2 % | 2 мар. 2007 г. |
20Наблюдать | CVE-2007-1832Эксплойта нет | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percweb-app.org · webapp | Средняя5,0 | — | 1,2 % | 2 апр. 2007 г. |
20Наблюдать | CVE-2007-1181Эксплойта нет | WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack veweb-app.org · webapp | Средняя5,0 | — | 1,1 % | 2 мар. 2007 г. |
20Наблюдать | CVE-2007-1186Эксплойта нет | WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.web-app.org · webapp | Средняя5,0 | — | 1,1 % | 2 мар. 2007 г. |
20Наблюдать | CVE-2007-1185Эксплойта нет | The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown iweb-app.org · webapp | Средняя5,0 | — | 1,1 % | 2 мар. 2007 г. |
- CVE-2005-092740В плане
Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharac
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %web-app.org · webapp2 мая 2005 г.
- CVE-2005-162833Наблюдать
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %web-app.org · webapp17 мая 2005 г.
- CVE-2007-324231Наблюдать
The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %web-app.net · webapp14 июн. 2007 г.
- CVE-2007-118830Наблюдать
WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has u
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-118330Наблюдать
WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attac
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-117830Наблюдать
WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-125930Наблюдать
Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp3 мар. 2007 г.
- CVE-2007-342430Наблюдать
The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory nam
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-341930Наблюдать
The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) la
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-342030Наблюдать
The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not c
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-342130Наблюдать
The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gall
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-342230Наблюдать
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-pri
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-342330Наблюдать
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .da
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-148927Наблюдать
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin acces
СредняяCVSS 6,8Эксплойта нетEPSS 1 %web-app.org · webapp16 мар. 2007 г.
- CVE-2007-341826Наблюдать
The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction
СредняяCVSS 6,5Эксплойта нетEPSS 1 %web-app.org · webapp26 июн. 2007 г.
- CVE-2007-182725Наблюдать
Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corru
СредняяCVSS 6,0Эксплойта нетEPSS 2 %web-app.org · webapp2 апр. 2007 г.
- CVE-2007-118225Наблюдать
WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.
СредняяCVSS 6,4Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-183124Наблюдать
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.
СредняяCVSS 6,0Эксплойта нетEPSS 1 %web-app.org · webapp2 апр. 2007 г.
- CVE-2007-117723Наблюдать
WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum P
СредняяCVSS 5,8Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2004-174222Наблюдать
Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 7 %web-app.org · webapp24 авг. 2004 г.
- CVE-2007-118722Наблюдать
WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive
СредняяCVSS 5,5Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-183220Наблюдать
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using perc
СредняяCVSS 5,0Эксплойта нетEPSS 1 %web-app.org · webapp2 апр. 2007 г.
- CVE-2007-118120Наблюдать
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack ve
СредняяCVSS 5,0Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-118620Наблюдать
WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.
- CVE-2007-118520Наблюдать
The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown i
СредняяCVSS 5,0Эксплойта нетEPSS 1 %web-app.org · webapp2 мар. 2007 г.