aspindir kayıtları
aspindir üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 19
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')19
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-2882Kavram kanıtı | upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file oraspindir · shibby shop · CWE-264 | Yüksek7,5 | — | %2,6 | 26 Haz 2008 |
31İzleyin | CVE-2008-2448Kavram kanıtı | Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter taspindir · meto forum · CWE-89 | Yüksek7,5 | — | %2,3 | 27 May 2008 |
31İzleyin | CVE-2007-3884Kavram kanıtı | SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the foaspindir · husrevforum · CWE-89 | Yüksek7,5 | — | %1,9 | 18 Tem 2007 |
30İzleyin | CVE-2006-7161İstismar yok | SQL injection vulnerability in giris_yap.asp in Hazir Site 2.0 allows remote attackers to bypass authentication via the (1) k_a class or (2)aspindir · hazirsite | Yüksek7,5 | — | %1,3 | 7 Mar 2007 |
30İzleyin | CVE-2006-6337Kavram kanıtı | Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQLaspindir · aspee ziyaretci defteri · CWE-89 | Yüksek7,5 | — | %1,2 | 6 Ara 2006 |
30İzleyin | CVE-2006-5023Kavram kanıtı | SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kataspindir · xweblog | Yüksek7,5 | — | %1,1 | 27 Eyl 2006 |
30İzleyin | CVE-2008-4574Kavram kanıtı | SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid paraspindir · ayco okul portali · CWE-89 | Yüksek7,5 | — | %1,0 | 15 Eki 2008 |
30İzleyin | CVE-2008-4573Kavram kanıtı | SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kaaspindir · munzursoft web portal w3 · CWE-89 | Yüksek7,5 | — | %1,0 | 15 Eki 2008 |
30İzleyin | CVE-2010-4144Kavram kanıtı | SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameaspindir · kisisel radyo script · CWE-89 | Yüksek7,5 | — | %1,0 | 1 Kas 2010 |
30İzleyin | CVE-2008-5057Kavram kanıtı | SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film aspindir · dizi portali · CWE-89 | Yüksek7,5 | — | %1,0 | 13 Kas 2008 |
30İzleyin | CVE-2008-2047Kavram kanıtı | Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to aspindir · angelo-emlak · CWE-89 | Yüksek7,5 | — | %1,0 | 1 May 2008 |
30İzleyin | CVE-2009-0447Kavram kanıtı | Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1)aspindir · mydesign sayac · CWE-89 | Yüksek7,5 | — | %1,0 | 10 Şub 2009 |
30İzleyin | CVE-2010-4855Kavram kanıtı | SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.aspindir · xweblog · CWE-89 | Yüksek7,5 | — | %1,0 | 5 Eki 2011 |
30İzleyin | CVE-2008-2334Kavram kanıtı | Multiple SQL injection vulnerabilities in W1L3D4 Philboard 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) forumid aspindir · philboard · CWE-89 | Yüksek7,5 | — | %1,0 | 19 May 2008 |
30İzleyin | CVE-2008-2872Kavram kanıtı | SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the aspindir · shibby shop · CWE-89 | Yüksek7,5 | — | %1,0 | 26 Haz 2008 |
30İzleyin | CVE-2008-6640Kavram kanıtı | Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) aspindir · batmanportal · CWE-89 | Yüksek7,5 | — | %1,0 | 7 Nis 2009 |
30İzleyin | CVE-2008-1939Kavram kanıtı | Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (aspindir · philboard · CWE-89 | Yüksek7,5 | — | %1,0 | 25 Nis 2008 |
30İzleyin | CVE-2008-3495Kavram kanıtı | SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameteraspindir · pcshey portal · CWE-89 | Yüksek7,5 | — | %1,0 | 6 Ağu 2008 |
30İzleyin | CVE-2008-5707Kavram kanıtı | SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the caaspindir · iltaweb alisveris sistemi · CWE-89 | Yüksek7,5 | — | %0,9 | 24 Ara 2008 |
30İzleyin | CVE-2010-4856Kavram kanıtı | SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.aspindir · xweblog · CWE-89 | Yüksek7,5 | — | %0,9 | 5 Eki 2011 |
30İzleyin | CVE-2008-3888Kavram kanıtı | SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid paspindir · mini nuke freehost · CWE-89 | Yüksek7,5 | — | %0,9 | 2 Eyl 2008 |
26İzleyin | CVE-2008-6641Kavram kanıtı | Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via taspindir · shader tv · CWE-89 | Orta6,5 | — | %0,9 | 7 Nis 2009 |
21İzleyin | CVE-2009-4585Kavram kanıtı | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers aspindir · uranyumsoft listing service · CWE-264 | Orta5,0 | — | %2,6 | 6 Oca 2010 |
21İzleyin | CVE-2008-2873Kavram kanıtı | sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers aspindir · shibby shop · CWE-264 | Orta5,0 | — | %2,6 | 26 Haz 2008 |
21İzleyin | CVE-2010-1064Kavram kanıtı | Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to downaspindir · erolife ajxgaleri vt · CWE-264 | Orta5,0 | — | %2,5 | 23 Mar 2010 |
- CVE-2008-288231İzleyin
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or
YüksekCVSS 7,5Kavram kanıtıEPSS %3aspindir · shibby shop26 Haz 2008
- CVE-2008-244831İzleyin
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter t
YüksekCVSS 7,5Kavram kanıtıEPSS %2aspindir · meto forum27 May 2008
- CVE-2007-388431İzleyin
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the fo
YüksekCVSS 7,5Kavram kanıtıEPSS %2aspindir · husrevforum18 Tem 2007
- CVE-2006-716130İzleyin
SQL injection vulnerability in giris_yap.asp in Hazir Site 2.0 allows remote attackers to bypass authentication via the (1) k_a class or (2)
YüksekCVSS 7,5İstismar yokEPSS %1aspindir · hazirsite7 Mar 2007
- CVE-2006-633730İzleyin
Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQL
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · aspee ziyaretci defteri6 Ara 2006
- CVE-2006-502330İzleyin
SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kat
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · xweblog27 Eyl 2006
- CVE-2008-457430İzleyin
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid par
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · ayco okul portali15 Eki 2008
- CVE-2008-457330İzleyin
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the ka
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · munzursoft web portal w315 Eki 2008
- CVE-2010-414430İzleyin
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parame
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · kisisel radyo script1 Kas 2010
- CVE-2008-505730İzleyin
SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · dizi portali13 Kas 2008
- CVE-2008-204730İzleyin
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · angelo-emlak1 May 2008
- CVE-2009-044730İzleyin
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · mydesign sayac10 Şub 2009
- CVE-2010-485530İzleyin
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · xweblog5 Eki 2011
- CVE-2008-233430İzleyin
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) forumid
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · philboard19 May 2008
- CVE-2008-287230İzleyin
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · shibby shop26 Haz 2008
- CVE-2008-664030İzleyin
Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · batmanportal7 Nis 2009
- CVE-2008-193930İzleyin
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · philboard25 Nis 2008
- CVE-2008-349530İzleyin
SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · pcshey portal6 Ağu 2008
- CVE-2008-570730İzleyin
SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the ca
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · iltaweb alisveris sistemi24 Ara 2008
- CVE-2010-485630İzleyin
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · xweblog5 Eki 2011
- CVE-2008-388830İzleyin
SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid p
YüksekCVSS 7,5Kavram kanıtıEPSS %1aspindir · mini nuke freehost2 Eyl 2008
- CVE-2008-664126İzleyin
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via t
OrtaCVSS 6,5Kavram kanıtıEPSS %1aspindir · shader tv7 Nis 2009
- CVE-2009-458521İzleyin
UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers
OrtaCVSS 5,0Kavram kanıtıEPSS %3aspindir · uranyumsoft listing service6 Oca 2010
- CVE-2008-287321İzleyin
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers
OrtaCVSS 5,0Kavram kanıtıEPSS %3aspindir · shibby shop26 Haz 2008
- CVE-2010-106421İzleyin
Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to down
OrtaCVSS 5,0Kavram kanıtıEPSS %2aspindir · erolife ajxgaleri vt23 Mar 2010