bitweaver kayıtları
bitweaver üreticisine ait 32 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,1
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
32 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2012-5192Silahlaştırılmış | Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vibitweaver · bitweaver · CWE-22 | Orta5,0 | — | %52,5 | 27 Oca 2014 |
31İzleyin | CVE-2007-6650Kavram kanıtı | Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using bitweaver · r2 cms · CWE-264 | Yüksek7,5 | — | %2,9 | 4 Oca 2008 |
31İzleyin | CVE-2009-1678Kavram kanıtı | Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackersbitweaver · bitweaver · CWE-22 | Yüksek7,5 | — | %2,4 | 18 May 2009 |
31İzleyin | CVE-2005-4380Kavram kanıtı | Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) bitweaver · bitweaver · CWE-89 | Yüksek7,5 | — | %2,2 | 19 Ara 2005 |
30İzleyin | CVE-2006-6923Kavram kanıtı | SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commabitweaver · bitweaver | Yüksek7,5 | — | %1,1 | 12 Oca 2007 |
30İzleyin | CVE-2007-6375Kavram kanıtı | Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbitweaver · bitweaver · CWE-89 | Yüksek7,5 | — | %1,0 | 14 Ara 2007 |
28İzleyin | CVE-2006-6925Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or bitweaver · bitweaver | Orta6,8 | — | %2,1 | 12 Oca 2007 |
27İzleyin | CVE-2009-1677Kavram kanıtı | Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) bitweaver · bitweaver · CWE-94 | Orta6,5 | — | %2,1 | 18 May 2009 |
27İzleyin | CVE-2007-6412İstismar yok | Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackbitweaver · bitweaver · CWE-94 | Orta6,8 | — | %1,5 | 17 Ara 2007 |
25İzleyin | CVE-2012-5193Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or bitweaver · bitweaver · CWE-79 | Orta6,1 | — | %1,8 | 13 Kas 2019 |
23İzleyin | CVE-2006-3104Kavram kanıtı | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals tbitweaver · bitweaver | Orta5,0 | — | %8,9 | 20 Haz 2006 |
23İzleyin | CVE-2006-3102Kavram kanıtı | Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execubitweaver · bitweaver | Orta5,1 | — | %8,5 | 20 Haz 2006 |
21İzleyin | CVE-2007-6651Kavram kanıtı | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourcbitweaver · bitweaver · CWE-22 | Orta5,0 | — | %3,7 | 4 Oca 2008 |
21İzleyin | CVE-2006-6924Kavram kanıtı | bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogsbitweaver · bitweaver | Orta5,0 | — | %3,4 | 12 Oca 2007 |
21İzleyin | CVE-2006-3105Kavram kanıtı | CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mubitweaver · bitweaver | Orta5,0 | — | %2,7 | 20 Haz 2006 |
21İzleyin | CVE-2010-5086İstismar yok | Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..bitweaver · bitweaver · CWE-22 | Orta5,0 | — | %1,8 | 19 Mar 2012 |
19İzleyin | CVE-2021-29031İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/userbitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,9 | 24 Mar 2021 |
19İzleyin | CVE-2021-29025İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.bitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29032İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preferencebitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29030İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/indebitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29029İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_persobitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29028İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/userbitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29027İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php bitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29026İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/permbitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
19İzleyin | CVE-2021-29033İstismar yok | A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/editbitweaver · bitweaver · CWE-79 | Orta4,8 | — | %0,8 | 24 Mar 2021 |
- CVE-2012-519236İzleyin
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files vi
OrtaCVSS 5,0SilahlaştırılmışEPSS %52bitweaver · bitweaver27 Oca 2014
- CVE-2007-665031İzleyin
Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using
YüksekCVSS 7,5Kavram kanıtıEPSS %3bitweaver · r2 cms4 Oca 2008
- CVE-2009-167831İzleyin
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers
YüksekCVSS 7,5Kavram kanıtıEPSS %2bitweaver · bitweaver18 May 2009
- CVE-2005-438031İzleyin
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %2bitweaver · bitweaver19 Ara 2005
- CVE-2006-692330İzleyin
SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5Kavram kanıtıEPSS %1bitweaver · bitweaver12 Oca 2007
- CVE-2007-637530İzleyin
Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s
YüksekCVSS 7,5Kavram kanıtıEPSS %1bitweaver · bitweaver14 Ara 2007
- CVE-2006-692528İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 6,8Kavram kanıtıEPSS %2bitweaver · bitweaver12 Oca 2007
- CVE-2009-167727İzleyin
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1)
OrtaCVSS 6,5Kavram kanıtıEPSS %2bitweaver · bitweaver18 May 2009
- CVE-2007-641227İzleyin
Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attack
OrtaCVSS 6,8İstismar yokEPSS %2bitweaver · bitweaver17 Ara 2007
- CVE-2012-519325İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 6,1Kavram kanıtıEPSS %2bitweaver · bitweaver13 Kas 2019
- CVE-2006-310423İzleyin
users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals t
OrtaCVSS 5,0Kavram kanıtıEPSS %9bitweaver · bitweaver20 Haz 2006
- CVE-2006-310223İzleyin
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execu
OrtaCVSS 5,1Kavram kanıtıEPSS %8bitweaver · bitweaver20 Haz 2006
- CVE-2007-665121İzleyin
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script sourc
OrtaCVSS 5,0Kavram kanıtıEPSS %4bitweaver · bitweaver4 Oca 2008
- CVE-2006-692421İzleyin
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs
OrtaCVSS 5,0Kavram kanıtıEPSS %3bitweaver · bitweaver12 Oca 2007
- CVE-2006-310521İzleyin
CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in mu
OrtaCVSS 5,0Kavram kanıtıEPSS %3bitweaver · bitweaver20 Haz 2006
- CVE-2010-508621İzleyin
Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0İstismar yokEPSS %2bitweaver · bitweaver19 Mar 2012
- CVE-2021-2903119İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2902519İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/my_images.
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2903219İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/preference
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2903019İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/inde
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2902919İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/edit_perso
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2902819İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/user
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2902719İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/index.php
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2902619İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/perm
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021
- CVE-2021-2903319İzleyin
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit
OrtaCVSS 4,8İstismar yokEPSS %1bitweaver · bitweaver24 Mar 2021