ajsquare kayıtları
ajsquare üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-287 Improper Authentication4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-7041Kavram kanıtı | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.ajsquare · aj classifieds · CWE-287 | Yüksek7,5 | — | %2,8 | 24 Ağu 2009 |
31İzleyin | CVE-2008-7051Kavram kanıtı | AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) useajsquare · aj article · CWE-287 | Yüksek7,5 | — | %2,5 | 24 Ağu 2009 |
30İzleyin | CVE-2008-7044Kavram kanıtı | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers ajsquare · free polling script · CWE-89 | Yüksek7,5 | — | %1,0 | 24 Ağu 2009 |
30İzleyin | CVE-2009-2779Kavram kanıtı | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in ajsquare · aj matrix dna · CWE-89 | Yüksek7,5 | — | %1,0 | 17 Ağu 2009 |
30İzleyin | CVE-2009-3203Kavram kanıtı | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parajsquare · aj auction pro-oopd · CWE-89 | Yüksek7,5 | — | %1,0 | 16 Eyl 2009 |
30İzleyin | CVE-2010-1876Kavram kanıtı | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatidajsquare · aj shopping cart · CWE-89 | Yüksek7,5 | — | %1,0 | 12 May 2010 |
30İzleyin | CVE-2010-2915Kavram kanıtı | SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id pajsquare · aj hyip · CWE-89 | Yüksek7,5 | — | %1,0 | 30 Tem 2010 |
30İzleyin | CVE-2008-6721Kavram kanıtı | SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName pajsquare · aj article · CWE-89 | Yüksek7,5 | — | %1,0 | 14 Nis 2009 |
30İzleyin | CVE-2010-2916Kavram kanıtı | SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id pajsquare · aj hyip · CWE-89 | Yüksek7,5 | — | %1,0 | 30 Tem 2010 |
26İzleyin | CVE-2008-7045Kavram kanıtı | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct rajsquare · free polling script · CWE-287 | Orta6,4 | — | %2,6 | 24 Ağu 2009 |
26İzleyin | CVE-2008-7046Kavram kanıtı | AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/iajsquare · free polling script · CWE-287 | Orta6,4 | — | %2,2 | 24 Ağu 2009 |
23İzleyin | CVE-2015-2184Kavram kanıtı | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.ajsquare · zeuscart · CWE-200 | Orta5,0 | — | %8,4 | 10 Mar 2015 |
18İzleyin | CVE-2015-2182Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ajsquare · zeuscart · CWE-79 | Orta4,3 | — | %4,5 | 11 Mar 2015 |
18İzleyin | CVE-2010-5322Kavram kanıtı | Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the ajsquare · zeuscart · CWE-79 | Orta4,3 | — | %2,6 | 11 Mar 2015 |
18İzleyin | CVE-2010-2917Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web ajsquare · aj article · CWE-79 | Orta4,3 | — | %1,7 | 30 Tem 2010 |
17İzleyin | CVE-2009-4989Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or Hajsquare · aj auction pro-oopd · CWE-79 | Orta4,3 | — | %1,5 | 25 Ağu 2010 |
- CVE-2008-704131İzleyin
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
YüksekCVSS 7,5Kavram kanıtıEPSS %3ajsquare · aj classifieds24 Ağu 2009
- CVE-2008-705131İzleyin
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) use
YüksekCVSS 7,5Kavram kanıtıEPSS %3ajsquare · aj article24 Ağu 2009
- CVE-2008-704430İzleyin
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · free polling script24 Ağu 2009
- CVE-2009-277930İzleyin
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj matrix dna17 Ağu 2009
- CVE-2009-320330İzleyin
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id par
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj auction pro-oopd16 Eyl 2009
- CVE-2010-187630İzleyin
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj shopping cart12 May 2010
- CVE-2010-291530İzleyin
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id p
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj hyip30 Tem 2010
- CVE-2008-672130İzleyin
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName p
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj article14 Nis 2009
- CVE-2010-291630İzleyin
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id p
YüksekCVSS 7,5Kavram kanıtıEPSS %1ajsquare · aj hyip30 Tem 2010
- CVE-2008-704526İzleyin
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct r
OrtaCVSS 6,4Kavram kanıtıEPSS %3ajsquare · free polling script24 Ağu 2009
- CVE-2008-704626İzleyin
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/i
OrtaCVSS 6,4Kavram kanıtıEPSS %2ajsquare · free polling script24 Ağu 2009
- CVE-2015-218423İzleyin
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.
OrtaCVSS 5,0Kavram kanıtıEPSS %8ajsquare · zeuscart10 Mar 2015
- CVE-2015-218218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1)
OrtaCVSS 4,3Kavram kanıtıEPSS %4ajsquare · zeuscart11 Mar 2015
- CVE-2010-532218İzleyin
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 4,3Kavram kanıtıEPSS %3ajsquare · zeuscart11 Mar 2015
- CVE-2010-291718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2ajsquare · aj article30 Tem 2010
- CVE-2009-498917İzleyin
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or H
OrtaCVSS 4,3Kavram kanıtıEPSS %1ajsquare · aj auction pro-oopd25 Ağu 2010