jelsoft kayıtları
jelsoft üreticisine ait 60 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,7
- Pre-auth RCE
- 19
- Düzeltme kaydı olan
- %1,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-189 Numeric Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
60 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2005-0511Silahlaştırılmış | misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitraryjelsoft · vbulletin | Yüksek7,5 | — | %35,8 | 21 Şub 2005 |
38İzleyin | CVE-2007-4120İstismar yok | Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URLjelsoft · vbulletin | Kritik9,3 | — | %2,1 | 1 Ağu 2007 |
34İzleyin | CVE-2007-2911İstismar yok | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to executjelsoft · vbulletin | Yüksek8,5 | — | %1,3 | 30 May 2007 |
33İzleyin | CVE-2002-1660Kavram kanıtı | calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parametjelsoft · vbulletin · CWE-78 | Yüksek7,5 | — | %11,1 | 31 Ara 2002 |
31İzleyin | CVE-2005-3019Kavram kanıtı | Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) requesjelsoft · vbulletin | Yüksek7,5 | — | %3,9 | 21 Eyl 2005 |
31İzleyin | CVE-2001-0475İstismar yok | index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote ajelsoft · vbulletin | Yüksek7,5 | — | %2,8 | 27 Haz 2001 |
31İzleyin | CVE-2006-4271İstismar yok | PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary Pjelsoft · vbulletin | Yüksek7,5 | — | %2,1 | 21 Ağu 2006 |
31İzleyin | CVE-2006-1382İstismar yok | PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remjelsoft · impex | Yüksek7,5 | — | %1,9 | 24 Mar 2006 |
31İzleyin | CVE-2004-2695İstismar yok | SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows rjelsoft · vbulletin · CWE-89 | Yüksek7,5 | — | %1,9 | 31 Ara 2004 |
30İzleyin | CVE-2006-4272İstismar yok | Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vijelsoft · vbulletin | Yüksek7,5 | — | %1,5 | 21 Ağu 2006 |
30İzleyin | CVE-2007-1292Kavram kanıtı | SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote autjelsoft · vbulletin | Yüksek7,5 | — | %1,3 | 6 Mar 2007 |
30İzleyin | CVE-2005-3024İstismar yok | Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ajelsoft · vbulletin | Yüksek7,5 | — | %1,2 | 21 Eyl 2005 |
30İzleyin | CVE-2005-3022İstismar yok | Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ajelsoft · vbulletin | Yüksek7,5 | — | %1,2 | 21 Eyl 2005 |
30İzleyin | CVE-2007-3196Kavram kanıtı | SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL comjelsoft · vbsupport integrated ticket system | Yüksek7,5 | — | %1,2 | 12 Haz 2007 |
30İzleyin | CVE-2006-2018İstismar yok | SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parjelsoft · vbulletin | Yüksek7,5 | — | %1,2 | 25 Nis 2006 |
30İzleyin | CVE-2006-5104Kavram kanıtı | SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatjelsoft · vbulletin | Yüksek7,5 | — | %1,1 | 3 Eki 2006 |
30İzleyin | CVE-2004-1515Kavram kanıtı | SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statemejelsoft · vbulletin | Yüksek7,5 | — | %1,0 | 31 Ara 2004 |
30İzleyin | CVE-2007-3197İstismar yok | SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspjelsoft · vbsupport integrated ticket system | Yüksek7,5 | — | %1,0 | 12 Haz 2007 |
28İzleyin | CVE-2006-6779Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF filejelsoft · vbulletin | Orta6,8 | — | %3,5 | 27 Ara 2006 |
28İzleyin | CVE-2006-6040Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrajelsoft · vbulletin | Orta6,8 | — | %2,2 | 21 Kas 2006 |
28İzleyin | CVE-2006-4273Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTMLjelsoft · vbulletin | Orta6,8 | — | %2,2 | 21 Ağu 2006 |
27İzleyin | CVE-2006-2335İstismar yok | Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administratorjelsoft · vbulletin | Orta6,5 | — | %3,4 | 11 May 2006 |
27İzleyin | CVE-2003-0295Kavram kanıtı | Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script anjelsoft · vbulletin | Orta6,8 | — | %1,6 | 16 Haz 2003 |
24İzleyin | CVE-2007-1573İstismar yok | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitjelsoft · vbulletin · CWE-89 | Orta6,0 | — | %0,9 | 21 Mar 2007 |
23İzleyin | CVE-2007-3326İstismar yok | Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .jelsoft · vbulletin | Orta5,8 | — | %1,2 | 21 Haz 2007 |
- CVE-2005-051141Planlayın
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary
YüksekCVSS 7,5SilahlaştırılmışEPSS %36jelsoft · vbulletin21 Şub 2005
- CVE-2007-412038İzleyin
Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL
KritikCVSS 9,3İstismar yokEPSS %2jelsoft · vbulletin1 Ağu 2007
- CVE-2007-291134İzleyin
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execut
YüksekCVSS 8,5İstismar yokEPSS %1jelsoft · vbulletin30 May 2007
- CVE-2002-166033İzleyin
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %11jelsoft · vbulletin31 Ara 2002
- CVE-2005-301931İzleyin
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) reques
YüksekCVSS 7,5Kavram kanıtıEPSS %4jelsoft · vbulletin21 Eyl 2005
- CVE-2001-047531İzleyin
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote a
YüksekCVSS 7,5İstismar yokEPSS %3jelsoft · vbulletin27 Haz 2001
- CVE-2006-427131İzleyin
PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary P
YüksekCVSS 7,5İstismar yokEPSS %2jelsoft · vbulletin21 Ağu 2006
- CVE-2006-138231İzleyin
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows rem
YüksekCVSS 7,5İstismar yokEPSS %2jelsoft · impex24 Mar 2006
- CVE-2004-269531İzleyin
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows r
YüksekCVSS 7,5İstismar yokEPSS %2jelsoft · vbulletin31 Ara 2004
- CVE-2006-427230İzleyin
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) vi
YüksekCVSS 7,5İstismar yokEPSS %2jelsoft · vbulletin21 Ağu 2006
- CVE-2007-129230İzleyin
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote aut
YüksekCVSS 7,5Kavram kanıtıEPSS %1jelsoft · vbulletin6 Mar 2007
- CVE-2005-302430İzleyin
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a
YüksekCVSS 7,5İstismar yokEPSS %1jelsoft · vbulletin21 Eyl 2005
- CVE-2005-302230İzleyin
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) a
YüksekCVSS 7,5İstismar yokEPSS %1jelsoft · vbulletin21 Eyl 2005
- CVE-2007-319630İzleyin
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL com
YüksekCVSS 7,5Kavram kanıtıEPSS %1jelsoft · vbsupport integrated ticket system12 Haz 2007
- CVE-2006-201830İzleyin
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid par
YüksekCVSS 7,5İstismar yokEPSS %1jelsoft · vbulletin25 Nis 2006
- CVE-2006-510430İzleyin
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templat
YüksekCVSS 7,5Kavram kanıtıEPSS %1jelsoft · vbulletin3 Eki 2006
- CVE-2004-151530İzleyin
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL stateme
YüksekCVSS 7,5Kavram kanıtıEPSS %1jelsoft · vbulletin31 Ara 2004
- CVE-2007-319730İzleyin
SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unsp
YüksekCVSS 7,5İstismar yokEPSS %1jelsoft · vbsupport integrated ticket system12 Haz 2007
- CVE-2006-677928İzleyin
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file
OrtaCVSS 6,8Kavram kanıtıEPSS %4jelsoft · vbulletin27 Ara 2006
- CVE-2006-604028İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitra
OrtaCVSS 6,8Kavram kanıtıEPSS %2jelsoft · vbulletin21 Kas 2006
- CVE-2006-427328İzleyin
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 6,8Kavram kanıtıEPSS %2jelsoft · vbulletin21 Ağu 2006
- CVE-2006-233527İzleyin
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrator
OrtaCVSS 6,5İstismar yokEPSS %3jelsoft · vbulletin11 May 2006
- CVE-2003-029527İzleyin
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script an
OrtaCVSS 6,8Kavram kanıtıEPSS %2jelsoft · vbulletin16 Haz 2003
- CVE-2007-157324İzleyin
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbit
OrtaCVSS 6,0İstismar yokEPSS %1jelsoft · vbulletin21 Mar 2007
- CVE-2007-332623İzleyin
Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .
OrtaCVSS 5,8İstismar yokEPSS %1jelsoft · vbulletin21 Haz 2007