kwsphp kayıtları
kwsphp üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2007-4956Kavram kanıtı | Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter tkwsphp · kwsphp · CWE-89 | Yüksek7,5 | — | %3,5 | 18 Eyl 2007 |
30İzleyin | CVE-2007-4979Kavram kanıtı | SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via kwsphp · kwsphp · CWE-89 | Yüksek7,5 | — | %1,0 | 19 Eyl 2007 |
30İzleyin | CVE-2007-5485Kavram kanıtı | SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the kwsphp · kwsphp · CWE-89 | Yüksek7,5 | — | %1,0 | 16 Eki 2007 |
30İzleyin | CVE-2008-1759Kavram kanıtı | SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parametjeuxflash · jeuxflash module · CWE-89 | Yüksek7,5 | — | %1,0 | 12 Nis 2008 |
30İzleyin | CVE-2008-1758Kavram kanıtı | SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID pakwsphp · kwsphp · CWE-89 | Yüksek7,5 | — | %1,0 | 12 Nis 2008 |
30İzleyin | CVE-2008-6197Kavram kanıtı | SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands kwsphp · kwsphp · CWE-89 | Yüksek7,5 | — | %1,0 | 19 Şub 2009 |
28İzleyin | CVE-2008-6201Kavram kanıtı | Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers kwsphp · kwsphp · CWE-22 | Orta6,8 | — | %3,1 | 19 Şub 2009 |
26İzleyin | CVE-2007-4922Kavram kanıtı | SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL cojeuxflash · jeuxflash module · CWE-89 | Orta6,5 | — | %0,9 | 17 Eyl 2007 |
17İzleyin | CVE-2008-1757Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrarykwsphp · kwsphp · CWE-79 | Orta4,3 | — | %1,5 | 12 Nis 2008 |
- CVE-2007-495631İzleyin
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter t
YüksekCVSS 7,5Kavram kanıtıEPSS %4kwsphp · kwsphp18 Eyl 2007
- CVE-2007-497930İzleyin
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1kwsphp · kwsphp19 Eyl 2007
- CVE-2007-548530İzleyin
SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %1kwsphp · kwsphp16 Eki 2007
- CVE-2008-175930İzleyin
SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %1jeuxflash · jeuxflash module12 Nis 2008
- CVE-2008-175830İzleyin
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID pa
YüksekCVSS 7,5Kavram kanıtıEPSS %1kwsphp · kwsphp12 Nis 2008
- CVE-2008-619730İzleyin
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1kwsphp · kwsphp19 Şub 2009
- CVE-2008-620128İzleyin
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers
OrtaCVSS 6,8Kavram kanıtıEPSS %3kwsphp · kwsphp19 Şub 2009
- CVE-2007-492226İzleyin
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL co
OrtaCVSS 6,5Kavram kanıtıEPSS %1jeuxflash · jeuxflash module17 Eyl 2007
- CVE-2008-175717İzleyin
Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary
OrtaCVSS 4,3Kavram kanıtıEPSS %1kwsphp · kwsphp12 Nis 2008