bosdev kayıtları
bosdev üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2006-3527İstismar yok | Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code viabosdev · bosclassifieds classified ads | Yüksek7,5 | — | %4,3 | 11 Tem 2006 |
31İzleyin | CVE-2006-3957Kavram kanıtı | PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL inbosdev · bosdates | Yüksek7,5 | — | %2,5 | 1 Ağu 2006 |
30İzleyin | CVE-2005-3911Kavram kanıtı | Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands bosdev · bosdates | Yüksek7,5 | — | %1,2 | 30 Kas 2005 |
30İzleyin | CVE-2008-1838Kavram kanıtı | SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cabosdev · bosclassifieds ads systems · CWE-89 | Yüksek7,5 | — | %1,0 | 16 Nis 2008 |
30İzleyin | CVE-2008-6526Kavram kanıtı | SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id pbosdev · bos classifieds · CWE-89 | Yüksek7,5 | — | %1,0 | 25 Mar 2009 |
30İzleyin | CVE-2008-4703Kavram kanıtı | SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parabosdev · bosnews · CWE-89 | Yüksek7,5 | — | %1,0 | 23 Eki 2008 |
21İzleyin | CVE-2004-0275Kavram kanıtı | SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information andbosdev · bosdates | Orta5,0 | — | %2,6 | 23 Kas 2004 |
20İzleyin | CVE-2007-5835İstismar yok | Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new adminbosdev · bosnews · CWE-264 | Orta5,0 | — | %1,2 | 5 Kas 2007 |
17İzleyin | CVE-2008-1211İstismar yok | Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the bosdev · bosdates · CWE-79 | Orta4,3 | — | %1,0 | 7 Mar 2008 |
17İzleyin | CVE-2008-1224İstismar yok | Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrbosdev · bosclassifieds classified ads · CWE-79 | Orta4,3 | — | %1,0 | 10 Mar 2008 |
17İzleyin | CVE-2007-5834İstismar yok | Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT elebosdev · bosnews · CWE-79 | Orta4,3 | — | %1,0 | 5 Kas 2007 |
14İzleyin | CVE-2007-5833İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to injectbosdev · bosmarket business directory system · CWE-79 | Düşük3,5 | — | %0,7 | 5 Kas 2007 |
- CVE-2006-352731İzleyin
Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via
YüksekCVSS 7,5İstismar yokEPSS %4bosdev · bosclassifieds classified ads11 Tem 2006
- CVE-2006-395731İzleyin
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in
YüksekCVSS 7,5Kavram kanıtıEPSS %3bosdev · bosdates1 Ağu 2006
- CVE-2005-391130İzleyin
Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1bosdev · bosdates30 Kas 2005
- CVE-2008-183830İzleyin
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the ca
YüksekCVSS 7,5Kavram kanıtıEPSS %1bosdev · bosclassifieds ads systems16 Nis 2008
- CVE-2008-652630İzleyin
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id p
YüksekCVSS 7,5Kavram kanıtıEPSS %1bosdev · bos classifieds25 Mar 2009
- CVE-2008-470330İzleyin
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article para
YüksekCVSS 7,5Kavram kanıtıEPSS %1bosdev · bosnews23 Eki 2008
- CVE-2004-027521İzleyin
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and
OrtaCVSS 5,0Kavram kanıtıEPSS %3bosdev · bosdates23 Kas 2004
- CVE-2007-583520İzleyin
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin
OrtaCVSS 5,0İstismar yokEPSS %1bosdev · bosnews5 Kas 2007
- CVE-2008-121117İzleyin
Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the
OrtaCVSS 4,3İstismar yokEPSS %1bosdev · bosdates7 Mar 2008
- CVE-2008-122417İzleyin
Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitr
OrtaCVSS 4,3İstismar yokEPSS %1bosdev · bosclassifieds classified ads10 Mar 2008
- CVE-2007-583417İzleyin
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT ele
OrtaCVSS 4,3İstismar yokEPSS %1bosdev · bosnews5 Kas 2007
- CVE-2007-583314İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject
DüşükCVSS 3,5İstismar yokEPSS %1bosdev · bosmarket business directory system5 Kas 2007