İçeriğe atla
Noroxi

jelsoft kayıtları

jelsoft üreticisine ait 60 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %1,7
Pre-auth RCE
19
Düzeltme kaydı olan
%1,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

60 kayıt
  • CVE-2005-0511
    41Planlayın

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary

    YüksekCVSS 7,5SilahlaştırılmışEPSS %36

    jelsoft · vbulletin21 Şub 2005

  • CVE-2007-4120
    38İzleyin

    Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL

    KritikCVSS 9,3İstismar yokEPSS %2

    jelsoft · vbulletin1 Ağu 2007

  • CVE-2007-2911
    34İzleyin

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execut

    YüksekCVSS 8,5İstismar yokEPSS %1

    jelsoft · vbulletin30 May 2007

  • CVE-2002-1660
    33İzleyin

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command paramet

    YüksekCVSS 7,5Kavram kanıtıEPSS %11

    jelsoft · vbulletin31 Ara 2002

  • CVE-2005-3019
    31İzleyin

    Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) reques

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    jelsoft · vbulletin21 Eyl 2005

  • CVE-2001-0475
    31İzleyin

    index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote a

    YüksekCVSS 7,5İstismar yokEPSS %3

    jelsoft · vbulletin27 Haz 2001

  • CVE-2006-4271
    31İzleyin

    PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary P

    YüksekCVSS 7,5İstismar yokEPSS %2

    jelsoft · vbulletin21 Ağu 2006

  • CVE-2006-1382
    31İzleyin

    PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows rem

    YüksekCVSS 7,5İstismar yokEPSS %2

    jelsoft · impex24 Mar 2006

  • CVE-2004-2695
    31İzleyin

    SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows r

    YüksekCVSS 7,5İstismar yokEPSS %2

    jelsoft · vbulletin31 Ara 2004

  • CVE-2006-4272
    30İzleyin

    Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vi

    YüksekCVSS 7,5İstismar yokEPSS %2

    jelsoft · vbulletin21 Ağu 2006

  • CVE-2007-1292
    30İzleyin

    SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote aut

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    jelsoft · vbulletin6 Mar 2007

  • CVE-2005-3024
    30İzleyin

    Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a

    YüksekCVSS 7,5İstismar yokEPSS %1

    jelsoft · vbulletin21 Eyl 2005

  • CVE-2005-3022
    30İzleyin

    Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a

    YüksekCVSS 7,5İstismar yokEPSS %1

    jelsoft · vbulletin21 Eyl 2005

  • CVE-2007-3196
    30İzleyin

    SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL com

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    jelsoft · vbsupport integrated ticket system12 Haz 2007

  • CVE-2006-2018
    30İzleyin

    SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid par

    YüksekCVSS 7,5İstismar yokEPSS %1

    jelsoft · vbulletin25 Nis 2006

  • CVE-2006-5104
    30İzleyin

    SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templat

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    jelsoft · vbulletin3 Eki 2006

  • CVE-2004-1515
    30İzleyin

    SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL stateme

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    jelsoft · vbulletin31 Ara 2004

  • CVE-2007-3197
    30İzleyin

    SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unsp

    YüksekCVSS 7,5İstismar yokEPSS %1

    jelsoft · vbsupport integrated ticket system12 Haz 2007

  • CVE-2006-6779
    28İzleyin

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file

    OrtaCVSS 6,8Kavram kanıtıEPSS %4

    jelsoft · vbulletin27 Ara 2006

  • CVE-2006-6040
    28İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitra

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    jelsoft · vbulletin21 Kas 2006

  • CVE-2006-4273
    28İzleyin

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    jelsoft · vbulletin21 Ağu 2006

  • CVE-2006-2335
    27İzleyin

    Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrator

    OrtaCVSS 6,5İstismar yokEPSS %3

    jelsoft · vbulletin11 May 2006

  • CVE-2003-0295
    27İzleyin

    Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script an

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    jelsoft · vbulletin16 Haz 2003

  • CVE-2007-1573
    24İzleyin

    SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbit

    OrtaCVSS 6,0İstismar yokEPSS %1

    jelsoft · vbulletin21 Mar 2007

  • CVE-2007-3326
    23İzleyin

    Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .

    OrtaCVSS 5,8İstismar yokEPSS %1

    jelsoft · vbulletin21 Haz 2007