Перейти к содержимому
Noroxi

Записи Xoops

101 опубликованных записей вендора xoops.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
52
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

101 записей
  • CVE-2007-3236
    53В плане

    PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP

    ВысокаяCVSS 7,5Proof of conceptEPSS 77 %

    xoops · horoscope module14 июн. 2007 г.

  • CVE-2007-3057
    48В плане

    PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attacke

    СредняяCVSS 6,8Proof of conceptEPSS 69 %

    xoops · icontent module5 июн. 2007 г.

  • CVE-2007-3221
    47В плане

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to

    СредняяCVSS 6,8Proof of conceptEPSS 68 %

    xoops · xt-conteudo module14 июн. 2007 г.

  • CVE-2007-3237
    47В плане

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers

    СредняяCVSS 6,8Proof of conceptEPSS 68 %

    xoops · tinycontent module14 июн. 2007 г.

  • CVE-2007-3220
    46В плане

    PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attacke

    СредняяCVSS 6,8Proof of conceptEPSS 63 %

    xoops · cjay content module14 июн. 2007 г.

  • CVE-2017-11174
    39Наблюдать

    In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    xoops · xoops12 июл. 2017 г.

  • CVE-2023-36217
    36Наблюдать

    Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of t

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    xoops · xoops3 авг. 2023 г.

  • CVE-2007-3289
    34Наблюдать

    PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execut

    ВысокаяCVSS 7,5Proof of conceptEPSS 12 %

    xoops · wiwimod module20 июн. 2007 г.

  • CVE-2007-3222
    32Наблюдать

    PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PH

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    xoops · xfsection module14 июн. 2007 г.

  • CVE-2008-3296
    32Наблюдать

    Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary loc

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    xoops · xoops25 июл. 2008 г.

  • CVE-2007-1974
    32Наблюдать

    SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modul

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    wf-sections · wf-sections11 апр. 2007 г.

  • CVE-2007-2370
    31Наблюдать

    SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrar

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    xoops · john mordo jobs module30 апр. 2007 г.

  • CVE-2008-0612
    31Наблюдать

    Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    xoops · xoops6 февр. 2008 г.

  • CVE-2007-5188
    31Наблюдать

    Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops3 окт. 2007 г.

  • CVE-2007-1838
    31Наблюдать

    SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQ

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · friendfinder module2 апр. 2007 г.

  • CVE-2007-1979
    31Наблюдать

    SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQ

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · xoops popnupblog11 апр. 2007 г.

  • CVE-2007-1846
    31Наблюдать

    SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL c

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · malaika system myads module3 апр. 2007 г.

  • CVE-2008-7178
    31Наблюдать

    Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · xoops8 сент. 2009 г.

  • CVE-2007-0377
    31Наблюдать

    Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops19 янв. 2007 г.

  • CVE-2014-3935
    31Наблюдать

    SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL comm

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · glossaire module2 июн. 2014 г.

  • CVE-2007-1976
    31Наблюдать

    PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops virii info module11 апр. 2007 г.

  • CVE-2002-0217
    31Наблюдать

    Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on o

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops16 мая 2002 г.

  • CVE-2006-4417
    31Наблюдать

    SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_av

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops28 авг. 2006 г.

  • CVE-2009-4698
    31Наблюдать

    Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL comman

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    xoops · xoops15 мар. 2010 г.

  • CVE-2009-3963
    30Наблюдать

    Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xoops · xoops17 нояб. 2009 г.