boka kayıtları
boka üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2008-7267Kavram kanıtı | SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id paraboka · siteengine · CWE-89 | Yüksek7,5 | — | %1,2 | 1 Ara 2010 |
30İzleyin | CVE-2010-4357Kavram kanıtı | SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module paramboka · siteengine · CWE-89 | Yüksek7,5 | — | %1,0 | 1 Ara 2010 |
25İzleyin | CVE-2008-7269Kavram kanıtı | Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and boka · siteengine · CWE-20 | Orta5,8 | — | %8,2 | 1 Ara 2010 |
20İzleyin | CVE-2008-7268İstismar yok | The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in mboka · siteengine · CWE-200 | Orta5,0 | — | %1,6 | 1 Ara 2010 |
- CVE-2008-726730İzleyin
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id para
YüksekCVSS 7,5Kavram kanıtıEPSS %1boka · siteengine1 Ara 2010
- CVE-2010-435730İzleyin
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module param
YüksekCVSS 7,5Kavram kanıtıEPSS %1boka · siteengine1 Ara 2010
- CVE-2008-726925İzleyin
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and
OrtaCVSS 5,8Kavram kanıtıEPSS %8boka · siteengine1 Ara 2010
- CVE-2008-726820İzleyin
The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in m
OrtaCVSS 5,0İstismar yokEPSS %2boka · siteengine1 Ara 2010