Bloofox kayıtları
bloofox üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-404 Improper Resource Shutdown or Release1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-34752Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&acbloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %4,4 | 14 Haz 2023 |
40Planlayın | CVE-2023-34756Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charsetbloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %4,2 | 14 Haz 2023 |
40Planlayın | CVE-2023-34755Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.bloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %4,2 | 14 Haz 2023 |
40Planlayın | CVE-2023-34751Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&actibloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %4,2 | 14 Haz 2023 |
40Planlayın | CVE-2023-34753Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&acbloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %4,2 | 14 Haz 2023 |
40Planlayın | CVE-2023-34754Kavram kanıtı | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=pluginsbloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %3,4 | 14 Haz 2023 |
40Planlayın | CVE-2020-35760İstismar yok | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).bloofox · bloofoxcms · CWE-434 | Kritik9,8 | — | %1,9 | 16 Haz 2021 |
39İzleyin | CVE-2021-44610İstismar yok | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) ebloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %1,4 | 24 Şub 2022 |
39İzleyin | CVE-2020-36082İstismar yok | File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via craftbloofox · bloofoxcms · CWE-434 | Kritik9,8 | — | %1,2 | 11 Ağu 2023 |
39İzleyin | CVE-2023-34750İstismar yok | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projectbloofox · bloofoxcms · CWE-89 | Kritik9,8 | — | %1,0 | 14 Haz 2023 |
36İzleyin | CVE-2023-27812İstismar yok | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.bloofox · bloofoxcms · CWE-22 | Kritik9,1 | — | %1,2 | 13 Nis 2023 |
35İzleyin | CVE-2008-5748Kavram kanıtı | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files vibloofox · bloofoxcms · CWE-22 | Yüksek8,1 | — | %10,4 | 29 Ara 2008 |
35İzleyin | CVE-2020-36141İstismar yok | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Contebloofox · bloofoxcms · CWE-434 | Yüksek8,8 | — | %1,3 | 4 Haz 2021 |
35İzleyin | CVE-2022-28528İstismar yok | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edibloofox · bloofoxcms · CWE-434 | Yüksek8,8 | — | %1,3 | 26 Nis 2022 |
35İzleyin | CVE-2023-29597İstismar yok | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=bloofox · bloofoxcms · CWE-89 | Yüksek8,8 | — | %0,7 | 13 Nis 2023 |
30İzleyin | CVE-2010-4870Kavram kanıtı | SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender paramebloofox · bloofoxcms · CWE-89 | Yüksek7,5 | — | %1,2 | 7 Eki 2011 |
26İzleyin | CVE-2020-36142İstismar yok | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.bloofox · bloofoxcms · CWE-22 | Orta6,5 | — | %1,4 | 4 Haz 2021 |
26İzleyin | CVE-2023-23151İstismar yok | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.bloofox · bloofoxcms · CWE-404 | Orta6,5 | — | %1,0 | 26 Oca 2023 |
26İzleyin | CVE-2020-35759İstismar yok | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).bloofox · bloofoxcms · CWE-352 | Orta6,5 | — | %0,8 | 16 Haz 2021 |
26İzleyin | CVE-2020-36140İstismar yok | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=ebloofox · bloofoxcms · CWE-352 | Orta6,5 | — | %0,6 | 4 Haz 2021 |
21İzleyin | CVE-2020-35761İstismar yok | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.bloofox · bloofoxcms · CWE-79 | Orta5,4 | — | %0,8 | 16 Haz 2021 |
21İzleyin | CVE-2020-36139İstismar yok | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.bloofox · bloofoxcms · CWE-79 | Orta5,4 | — | %0,5 | 4 Haz 2021 |
21İzleyin | CVE-2021-44608İstismar yok | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter ibloofox · bloofoxcms · CWE-79 | Orta5,4 | — | %0,5 | 24 Şub 2022 |
19İzleyin | CVE-2020-35709İstismar yok | bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the bloofox · bloofoxcms · CWE-22 | Orta4,9 | — | %1,3 | 25 Ara 2020 |
17İzleyin | CVE-2009-4522Kavram kanıtı | Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTMLbloofox · bloofoxcms · CWE-79 | Orta4,3 | — | %1,5 | 31 Ara 2009 |
- CVE-2023-3475240Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&ac
KritikCVSS 9,8Kavram kanıtıEPSS %4bloofox · bloofoxcms14 Haz 2023
- CVE-2023-3475640Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset
KritikCVSS 9,8Kavram kanıtıEPSS %4bloofox · bloofoxcms14 Haz 2023
- CVE-2023-3475540Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
KritikCVSS 9,8Kavram kanıtıEPSS %4bloofox · bloofoxcms14 Haz 2023
- CVE-2023-3475140Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&acti
KritikCVSS 9,8Kavram kanıtıEPSS %4bloofox · bloofoxcms14 Haz 2023
- CVE-2023-3475340Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&ac
KritikCVSS 9,8Kavram kanıtıEPSS %4bloofox · bloofoxcms14 Haz 2023
- CVE-2023-3475440Planlayın
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins
KritikCVSS 9,8Kavram kanıtıEPSS %3bloofox · bloofoxcms14 Haz 2023
- CVE-2020-3576040Planlayın
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
KritikCVSS 9,8İstismar yokEPSS %2bloofox · bloofoxcms16 Haz 2021
- CVE-2021-4461039İzleyin
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) e
KritikCVSS 9,8İstismar yokEPSS %1bloofox · bloofoxcms24 Şub 2022
- CVE-2020-3608239İzleyin
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via craft
KritikCVSS 9,8İstismar yokEPSS %1bloofox · bloofoxcms11 Ağu 2023
- CVE-2023-3475039İzleyin
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=project
KritikCVSS 9,8İstismar yokEPSS %1bloofox · bloofoxcms14 Haz 2023
- CVE-2023-2781236İzleyin
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
KritikCVSS 9,1İstismar yokEPSS %1bloofox · bloofoxcms13 Nis 2023
- CVE-2008-574835İzleyin
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files vi
YüksekCVSS 8,1Kavram kanıtıEPSS %10bloofox · bloofoxcms29 Ara 2008
- CVE-2020-3614135İzleyin
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Conte
YüksekCVSS 8,8İstismar yokEPSS %1bloofox · bloofoxcms4 Haz 2021
- CVE-2022-2852835İzleyin
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edi
YüksekCVSS 8,8İstismar yokEPSS %1bloofox · bloofoxcms26 Nis 2022
- CVE-2023-2959735İzleyin
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=
YüksekCVSS 8,8İstismar yokEPSS %1bloofox · bloofoxcms13 Nis 2023
- CVE-2010-487030İzleyin
SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parame
YüksekCVSS 7,5Kavram kanıtıEPSS %1bloofox · bloofoxcms7 Eki 2011
- CVE-2020-3614226İzleyin
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
OrtaCVSS 6,5İstismar yokEPSS %1bloofox · bloofoxcms4 Haz 2021
- CVE-2023-2315126İzleyin
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
OrtaCVSS 6,5İstismar yokEPSS %1bloofox · bloofoxcms26 Oca 2023
- CVE-2020-3575926İzleyin
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
OrtaCVSS 6,5İstismar yokEPSS %1bloofox · bloofoxcms16 Haz 2021
- CVE-2020-3614026İzleyin
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=e
OrtaCVSS 6,5İstismar yokEPSS %1bloofox · bloofoxcms4 Haz 2021
- CVE-2020-3576121İzleyin
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
OrtaCVSS 5,4İstismar yokEPSS %1bloofox · bloofoxcms16 Haz 2021
- CVE-2020-3613921İzleyin
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
OrtaCVSS 5,4İstismar yokEPSS %1bloofox · bloofoxcms4 Haz 2021
- CVE-2021-4460821İzleyin
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter i
OrtaCVSS 5,4İstismar yokEPSS %0bloofox · bloofoxcms24 Şub 2022
- CVE-2020-3570919İzleyin
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the
OrtaCVSS 4,9İstismar yokEPSS %1bloofox · bloofoxcms25 Ara 2020
- CVE-2009-452217İzleyin
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %2bloofox · bloofoxcms31 Ara 2009