Записи Xoops
101 опубликованных записей вендора xoops.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 52
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')26
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
101 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2007-3236Proof of concept | PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHPxoops · horoscope module | Высокая7,5 | — | 77,0 % | 14 июн. 2007 г. |
48В плане | CVE-2007-3057Proof of concept | PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackexoops · icontent module | Средняя6,8 | — | 68,7 % | 5 июн. 2007 г. |
47В плане | CVE-2007-3221Proof of concept | PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to xoops · xt-conteudo module | Средняя6,8 | — | 67,8 % | 14 июн. 2007 г. |
47В плане | CVE-2007-3237Proof of concept | PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackersxoops · tinycontent module | Средняя6,8 | — | 67,7 % | 14 июн. 2007 г. |
46В плане | CVE-2007-3220Proof of concept | PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackexoops · cjay content module | Средняя6,8 | — | 62,7 % | 14 июн. 2007 г. |
39Наблюдать | CVE-2017-11174Эксплойта нет | In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL xoops · xoops · CWE-89 | Критическая9,8 | — | 1,0 % | 12 июл. 2017 г. |
36Наблюдать | CVE-2023-36217Эксплойта нет | Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of txoops · xoops · CWE-79 | Критическая9,0 | — | 1,6 % | 3 авг. 2023 г. |
34Наблюдать | CVE-2007-3289Proof of concept | PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to executxoops · wiwimod module | Высокая7,5 | — | 12,2 % | 20 июн. 2007 г. |
32Наблюдать | CVE-2007-3222Proof of concept | PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHxoops · xfsection module | Высокая7,5 | — | 7,4 % | 14 июн. 2007 г. |
32Наблюдать | CVE-2008-3296Proof of concept | Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary locxoops · xoops · CWE-22 | Высокая7,5 | — | 5,7 % | 25 июл. 2008 г. |
32Наблюдать | CVE-2007-1974Proof of concept | SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modulwf-sections · wf-sections | Высокая7,5 | — | 5,5 % | 11 апр. 2007 г. |
31Наблюдать | CVE-2007-2370Proof of concept | SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrarxoops · john mordo jobs module | Высокая7,5 | — | 2,9 % | 30 апр. 2007 г. |
31Наблюдать | CVE-2008-0612Proof of concept | Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary localxoops · xoops · CWE-22 | Высокая7,5 | — | 2,8 % | 6 февр. 2008 г. |
31Наблюдать | CVE-2007-5188Эксплойта нет | Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vixoops · xoops | Высокая7,5 | — | 2,4 % | 3 окт. 2007 г. |
31Наблюдать | CVE-2007-1838Proof of concept | SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQxoops · friendfinder module | Высокая7,5 | — | 2,2 % | 2 апр. 2007 г. |
31Наблюдать | CVE-2007-1979Proof of concept | SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQxoops · xoops popnupblog | Высокая7,5 | — | 2,2 % | 11 апр. 2007 г. |
31Наблюдать | CVE-2007-1846Proof of concept | SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL cxoops · malaika system myads module | Высокая7,5 | — | 2,2 % | 3 апр. 2007 г. |
31Наблюдать | CVE-2008-7178Proof of concept | Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..xoops · xoops · CWE-22 | Высокая7,5 | — | 2,2 % | 8 сент. 2009 г. |
31Наблюдать | CVE-2007-0377Эксплойта нет | Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in xoops · xoops | Высокая7,5 | — | 2,1 % | 19 янв. 2007 г. |
31Наблюдать | CVE-2014-3935Proof of concept | SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commxoops · glossaire module · CWE-89 | Высокая7,5 | — | 2,1 % | 2 июн. 2014 г. |
31Наблюдать | CVE-2007-1976Эксплойта нет | PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute xoops · xoops virii info module | Высокая7,5 | — | 2,0 % | 11 апр. 2007 г. |
31Наблюдать | CVE-2002-0217Эксплойта нет | Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on oxoops · xoops | Высокая7,5 | — | 1,8 % | 16 мая 2002 г. |
31Наблюдать | CVE-2006-4417Эксплойта нет | SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avxoops · xoops | Высокая7,5 | — | 1,7 % | 28 авг. 2006 г. |
31Наблюдать | CVE-2009-4698Proof of concept | Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commanxoops · xoops · CWE-89 | Высокая7,5 | — | 1,7 % | 15 мар. 2010 г. |
30Наблюдать | CVE-2009-3963Эксплойта нет | Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.xoops · xoops | Высокая7,5 | — | 1,6 % | 17 нояб. 2009 г. |
- CVE-2007-323653В плане
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP
ВысокаяCVSS 7,5Proof of conceptEPSS 77 %xoops · horoscope module14 июн. 2007 г.
- CVE-2007-305748В плане
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attacke
СредняяCVSS 6,8Proof of conceptEPSS 69 %xoops · icontent module5 июн. 2007 г.
- CVE-2007-322147В плане
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to
СредняяCVSS 6,8Proof of conceptEPSS 68 %xoops · xt-conteudo module14 июн. 2007 г.
- CVE-2007-323747В плане
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers
СредняяCVSS 6,8Proof of conceptEPSS 68 %xoops · tinycontent module14 июн. 2007 г.
- CVE-2007-322046В плане
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attacke
СредняяCVSS 6,8Proof of conceptEPSS 63 %xoops · cjay content module14 июн. 2007 г.
- CVE-2017-1117439Наблюдать
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xoops · xoops12 июл. 2017 г.
- CVE-2023-3621736Наблюдать
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of t
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %xoops · xoops3 авг. 2023 г.
- CVE-2007-328934Наблюдать
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execut
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %xoops · wiwimod module20 июн. 2007 г.
- CVE-2007-322232Наблюдать
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PH
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %xoops · xfsection module14 июн. 2007 г.
- CVE-2008-329632Наблюдать
Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary loc
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %xoops · xoops25 июл. 2008 г.
- CVE-2007-197432Наблюдать
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modul
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %wf-sections · wf-sections11 апр. 2007 г.
- CVE-2007-237031Наблюдать
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrar
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %xoops · john mordo jobs module30 апр. 2007 г.
- CVE-2008-061231Наблюдать
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %xoops · xoops6 февр. 2008 г.
- CVE-2007-518831Наблюдать
Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops3 окт. 2007 г.
- CVE-2007-183831Наблюдать
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · friendfinder module2 апр. 2007 г.
- CVE-2007-197931Наблюдать
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · xoops popnupblog11 апр. 2007 г.
- CVE-2007-184631Наблюдать
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL c
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · malaika system myads module3 апр. 2007 г.
- CVE-2008-717831Наблюдать
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a ..
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · xoops8 сент. 2009 г.
- CVE-2007-037731Наблюдать
Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops19 янв. 2007 г.
- CVE-2014-393531Наблюдать
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL comm
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · glossaire module2 июн. 2014 г.
- CVE-2007-197631Наблюдать
PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops virii info module11 апр. 2007 г.
- CVE-2002-021731Наблюдать
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on o
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops16 мая 2002 г.
- CVE-2006-441731Наблюдать
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_av
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops28 авг. 2006 г.
- CVE-2009-469831Наблюдать
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %xoops · xoops15 мар. 2010 г.
- CVE-2009-396330Наблюдать
Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xoops · xoops17 нояб. 2009 г.