Записи webidsupport
17 опубликованных записей вендора webidsupport.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-697 Incorrect Comparison1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-23359Эксплойта нет | WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the idenwebidsupport · webid · CWE-697 | Критическая9,8 | — | 1,2 % | 27 янв. 2021 г. |
39Наблюдать | CVE-2023-47397Эксплойта нет | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.webidsupport · webid · CWE-94 | Критическая9,8 | — | 1,0 % | 8 нояб. 2023 г. |
39Наблюдать | CVE-2024-35409Эксплойта нет | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.webidsupport · webid · CWE-89 | Критическая9,8 | — | 0,5 % | 22 мая 2024 г. |
36Наблюдать | CVE-2022-41477Эксплойта нет | A security issue was discovered in WeBid <=1.2.2.webidsupport · webid · CWE-918 | Критическая9,1 | — | 1,2 % | 14 окт. 2022 г. |
35Наблюдать | CVE-2018-1000867Эксплойта нет | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Dawebidsupport · webid · CWE-89 | Высокая8,8 | — | 1,5 % | 20 дек. 2018 г. |
35Наблюдать | CVE-2024-32166Эксплойта нет | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now anwebidsupport · webid · CWE-639 | Высокая8,8 | — | 0,7 % | 19 апр. 2024 г. |
31Наблюдать | CVE-2018-1000882Эксплойта нет | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fiwebidsupport · webid · CWE-22 | Высокая7,5 | — | 2,4 % | 20 дек. 2018 г. |
31Наблюдать | CVE-2014-5114Эксплойта нет | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.webidsupport · webid | Высокая7,5 | — | 2,1 % | 29 июл. 2014 г. |
30Наблюдать | CVE-2008-7116Proof of concept | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commawebidsupport · webid · CWE-89 | Высокая7,5 | — | 1,0 % | 28 авг. 2009 г. |
30Наблюдать | CVE-2008-7119Proof of concept | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id pwebidsupport · webid · CWE-89 | Высокая7,5 | — | 1,0 % | 28 авг. 2009 г. |
24Наблюдать | CVE-2018-1000868Эксплойта нет | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resulwebidsupport · webid · CWE-79 | Средняя6,1 | — | 1,6 % | 20 дек. 2018 г. |
24Наблюдать | CVE-2019-11592Эксплойта нет | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/webidsupport · webid · CWE-79 | Средняя6,1 | — | 0,8 % | 29 апр. 2019 г. |
21Наблюдать | CVE-2008-7118Proof of concept | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers twebidsupport · webid · CWE-264 | Средняя5,0 | — | 2,4 % | 28 авг. 2009 г. |
21Наблюдать | CVE-2011-3815Эксплойта нет | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pathwebidsupport · webid · CWE-200 | Средняя5,0 | — | 1,9 % | 23 сент. 2011 г. |
21Наблюдать | CVE-2008-7117Proof of concept | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requwebidsupport · webid · CWE-264 | Средняя5,0 | — | 1,7 % | 28 авг. 2009 г. |
18Наблюдать | CVE-2014-5101Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)webidsupport · webid · CWE-79 | Средняя4,3 | — | 2,5 % | 25 июл. 2014 г. |
18Наблюдать | CVE-2010-4873Proof of concept | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML viawebidsupport · webid · CWE-79 | Средняя4,3 | — | 1,8 % | 7 окт. 2011 г. |
- CVE-2020-2335939Наблюдать
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the iden
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %webidsupport · webid27 янв. 2021 г.
- CVE-2023-4739739Наблюдать
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %webidsupport · webid8 нояб. 2023 г.
- CVE-2024-3540939Наблюдать
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %webidsupport · webid22 мая 2024 г.
- CVE-2022-4147736Наблюдать
A security issue was discovered in WeBid <=1.2.2.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %webidsupport · webid14 окт. 2022 г.
- CVE-2018-100086735Наблюдать
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Da
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webidsupport · webid20 дек. 2018 г.
- CVE-2024-3216635Наблюдать
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webidsupport · webid19 апр. 2024 г.
- CVE-2018-100088231Наблюдать
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image Fi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %webidsupport · webid20 дек. 2018 г.
- CVE-2014-511431Наблюдать
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %webidsupport · webid29 июл. 2014 г.
- CVE-2008-711630Наблюдать
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webidsupport · webid28 авг. 2009 г.
- CVE-2008-711930Наблюдать
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webidsupport · webid28 авг. 2009 г.
- CVE-2018-100086824Наблюдать
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can resul
СредняяCVSS 6,1Эксплойта нетEPSS 2 %webidsupport · webid20 дек. 2018 г.
- CVE-2019-1159224Наблюдать
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/
СредняяCVSS 6,1Эксплойта нетEPSS 1 %webidsupport · webid29 апр. 2019 г.
- CVE-2008-711821Наблюдать
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers t
СредняяCVSS 5,0Proof of conceptEPSS 2 %webidsupport · webid28 авг. 2009 г.
- CVE-2011-381521Наблюдать
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
СредняяCVSS 5,0Эксплойта нетEPSS 2 %webidsupport · webid23 сент. 2011 г.
- CVE-2008-711721Наблюдать
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain requ
СредняяCVSS 5,0Proof of conceptEPSS 2 %webidsupport · webid28 авг. 2009 г.
- CVE-2014-510118Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)
СредняяCVSS 4,3Proof of conceptEPSS 3 %webidsupport · webid25 июл. 2014 г.
- CVE-2010-487318Наблюдать
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Proof of conceptEPSS 2 %webidsupport · webid7 окт. 2011 г.