Записи webspell
21 опубликованных записей вендора webspell.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-1160Эксплойта нет | webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability webspell · webspell · CWE-287 | Критическая10,0 | — | 2,7 % | 2 мар. 2007 г. |
30Наблюдать | CVE-2007-4028Эксплойта нет | Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files webspell · webspell | Высокая7,5 | — | 1,5 % | 26 июл. 2007 г. |
30Наблюдать | CVE-2010-4861Proof of concept | SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search paramewebspell · webspell · CWE-89 | Высокая7,5 | — | 1,2 % | 5 окт. 2011 г. |
30Наблюдать | CVE-2006-0728Proof of concept | SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the twebspell · webspell | Высокая7,5 | — | 1,2 % | 16 февр. 2006 г. |
30Наблюдать | CVE-2007-0502Proof of concept | SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID paramwebspell · webspell | Высокая7,5 | — | 1,1 % | 25 янв. 2007 г. |
30Наблюдать | CVE-2006-5388Proof of concept | SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the gwebspell · webspell | Высокая7,5 | — | 1,1 % | 18 окт. 2006 г. |
30Наблюдать | CVE-2007-1163Proof of concept | SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via twebspell · webspell · CWE-89 | Высокая7,5 | — | 1,1 % | 2 мар. 2007 г. |
30Наблюдать | CVE-2007-0492Эксплойта нет | Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commanwebspell · webspell | Высокая7,5 | — | 1,1 % | 24 янв. 2007 г. |
28Наблюдать | CVE-2009-1912Proof of concept | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbwebspell · webspell · CWE-22 | Средняя6,8 | — | 3,2 % | 4 июн. 2009 г. |
27Наблюдать | CVE-2007-1019Proof of concept | SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary webspell · webspell | Средняя6,8 | — | 1,2 % | 21 февр. 2007 г. |
27Наблюдать | CVE-2007-1154Эксплойта нет | SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerabwebspell · webspell · CWE-89 | Средняя6,8 | — | 1,0 % | 2 мар. 2007 г. |
23Наблюдать | CVE-2007-2369Proof of concept | Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to php · php | Средняя5,0 | — | 8,4 % | 30 апр. 2007 г. |
22Наблюдать | CVE-2006-4782Proof of concept | src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain swebspell · webspell | Средняя5,4 | — | 3,2 % | 14 сент. 2006 г. |
21Наблюдать | CVE-2007-2368Proof of concept | picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.webspell · webspell | Средняя5,0 | — | 2,3 % | 30 апр. 2007 г. |
20Наблюдать | CVE-2006-4783Эксплойта нет | SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execwebspell · webspell | Средняя5,1 | — | 1,2 % | 14 сент. 2006 г. |
18Наблюдать | CVE-2007-6309Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or webspell · webspell · CWE-79 | Средняя4,3 | — | 4,2 % | 11 дек. 2007 г. |
18Наблюдать | CVE-2009-1408Proof of concept | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attwebspell · webspell · CWE-79 | Средняя4,3 | — | 2,0 % | 24 апр. 2009 г. |
18Наблюдать | CVE-2007-1155Эксплойта нет | Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via twebspell · webspell · CWE-20 | Средняя4,6 | — | 1,0 % | 2 мар. 2007 г. |
17Наблюдать | CVE-2008-0574Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML viawebspell · webspell · CWE-79 | Средняя4,3 | — | 1,5 % | 4 февр. 2008 г. |
17Наблюдать | CVE-2008-1481Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via twebspell · webspell · CWE-79 | Средняя4,3 | — | 1,4 % | 24 мар. 2008 г. |
17Наблюдать | CVE-2008-0575Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmiwebspell · webspell · CWE-352 | Средняя4,3 | — | 0,5 % | 4 февр. 2008 г. |
- CVE-2007-116041В плане
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %webspell · webspell2 мар. 2007 г.
- CVE-2007-402830Наблюдать
Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %webspell · webspell26 июл. 2007 г.
- CVE-2010-486130Наблюдать
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parame
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webspell · webspell5 окт. 2011 г.
- CVE-2006-072830Наблюдать
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the t
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webspell · webspell16 февр. 2006 г.
- CVE-2007-050230Наблюдать
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID param
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webspell · webspell25 янв. 2007 г.
- CVE-2006-538830Наблюдать
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the g
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webspell · webspell18 окт. 2006 г.
- CVE-2007-116330Наблюдать
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via t
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %webspell · webspell2 мар. 2007 г.
- CVE-2007-049230Наблюдать
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %webspell · webspell24 янв. 2007 г.
- CVE-2009-191228Наблюдать
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arb
СредняяCVSS 6,8Proof of conceptEPSS 3 %webspell · webspell4 июн. 2009 г.
- CVE-2007-101927Наблюдать
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary
СредняяCVSS 6,8Proof of conceptEPSS 1 %webspell · webspell21 февр. 2007 г.
- CVE-2007-115427Наблюдать
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerab
СредняяCVSS 6,8Эксплойта нетEPSS 1 %webspell · webspell2 мар. 2007 г.
- CVE-2007-236923Наблюдать
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to
СредняяCVSS 5,0Proof of conceptEPSS 8 %php · php30 апр. 2007 г.
- CVE-2006-478222Наблюдать
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain s
СредняяCVSS 5,4Proof of conceptEPSS 3 %webspell · webspell14 сент. 2006 г.
- CVE-2007-236821Наблюдать
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
СредняяCVSS 5,0Proof of conceptEPSS 2 %webspell · webspell30 апр. 2007 г.
- CVE-2006-478320Наблюдать
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to exec
СредняяCVSS 5,1Эксплойта нетEPSS 1 %webspell · webspell14 сент. 2006 г.
- CVE-2007-630918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 4 %webspell · webspell11 дек. 2007 г.
- CVE-2009-140818Наблюдать
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote att
СредняяCVSS 4,3Proof of conceptEPSS 2 %webspell · webspell24 апр. 2009 г.
- CVE-2007-115518Наблюдать
Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via t
СредняяCVSS 4,6Эксплойта нетEPSS 1 %webspell · webspell2 мар. 2007 г.
- CVE-2008-057417Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Proof of conceptEPSS 2 %webspell · webspell4 февр. 2008 г.
- CVE-2008-148117Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 4,3Proof of conceptEPSS 1 %webspell · webspell24 мар. 2008 г.
- CVE-2008-057517Наблюдать
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %webspell · webspell4 февр. 2008 г.