Перейти к содержимому
Noroxi

Записи webspell

21 опубликованных записей вендора webspell.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
10
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

21 записей
  • CVE-2007-1160
    41В плане

    webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    webspell · webspell2 мар. 2007 г.

  • CVE-2007-4028
    30Наблюдать

    Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    webspell · webspell26 июл. 2007 г.

  • CVE-2010-4861
    30Наблюдать

    SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parame

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webspell · webspell5 окт. 2011 г.

  • CVE-2006-0728
    30Наблюдать

    SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the t

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webspell · webspell16 февр. 2006 г.

  • CVE-2007-0502
    30Наблюдать

    SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID param

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webspell · webspell25 янв. 2007 г.

  • CVE-2006-5388
    30Наблюдать

    SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the g

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webspell · webspell18 окт. 2006 г.

  • CVE-2007-1163
    30Наблюдать

    SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via t

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    webspell · webspell2 мар. 2007 г.

  • CVE-2007-0492
    30Наблюдать

    Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL comman

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    webspell · webspell24 янв. 2007 г.

  • CVE-2009-1912
    28Наблюдать

    Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arb

    СредняяCVSS 6,8Proof of conceptEPSS 3 %

    webspell · webspell4 июн. 2009 г.

  • CVE-2007-1019
    27Наблюдать

    SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    webspell · webspell21 февр. 2007 г.

  • CVE-2007-1154
    27Наблюдать

    SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerab

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    webspell · webspell2 мар. 2007 г.

  • CVE-2007-2369
    23Наблюдать

    Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to

    СредняяCVSS 5,0Proof of conceptEPSS 8 %

    php · php30 апр. 2007 г.

  • CVE-2006-4782
    22Наблюдать

    src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain s

    СредняяCVSS 5,4Proof of conceptEPSS 3 %

    webspell · webspell14 сент. 2006 г.

  • CVE-2007-2368
    21Наблюдать

    picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.

    СредняяCVSS 5,0Proof of conceptEPSS 2 %

    webspell · webspell30 апр. 2007 г.

  • CVE-2006-4783
    20Наблюдать

    SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to exec

    СредняяCVSS 5,1Эксплойта нетEPSS 1 %

    webspell · webspell14 сент. 2006 г.

  • CVE-2007-6309
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or

    СредняяCVSS 4,3Proof of conceptEPSS 4 %

    webspell · webspell11 дек. 2007 г.

  • CVE-2009-1408
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote att

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    webspell · webspell24 апр. 2009 г.

  • CVE-2007-1155
    18Наблюдать

    Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via t

    СредняяCVSS 4,6Эксплойта нетEPSS 1 %

    webspell · webspell2 мар. 2007 г.

  • CVE-2008-0574
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    webspell · webspell4 февр. 2008 г.

  • CVE-2008-1481
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via t

    СредняяCVSS 4,3Proof of conceptEPSS 1 %

    webspell · webspell24 мар. 2008 г.

  • CVE-2008-0575
    17Наблюдать

    Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmi

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    webspell · webspell4 февр. 2008 г.