maran kayıtları
maran üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-6296Kavram kanıtı | admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "dmaran · php shop · CWE-264 | Yüksek7,5 | — | %2,5 | 26 Şub 2009 |
30İzleyin | CVE-2008-4880Kavram kanıtı | SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parametermaran · php shop · CWE-89 | Yüksek7,5 | — | %1,2 | 3 Kas 2008 |
30İzleyin | CVE-2008-4879Kavram kanıtı | SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, amaran · php shop · CWE-89 | Yüksek7,5 | — | %1,0 | 3 Kas 2008 |
28İzleyin | CVE-2007-2182Kavram kanıtı | Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP filmaran · php forum | Orta6,8 | — | %4,4 | 24 Nis 2007 |
18İzleyin | CVE-2007-3198Kavram kanıtı | Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remomaran · php blog | Orta4,3 | — | %2,5 | 12 Haz 2007 |
- CVE-2008-629631İzleyin
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "d
YüksekCVSS 7,5Kavram kanıtıEPSS %3maran · php shop26 Şub 2009
- CVE-2008-488030İzleyin
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %1maran · php shop3 Kas 2008
- CVE-2008-487930İzleyin
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a
YüksekCVSS 7,5Kavram kanıtıEPSS %1maran · php shop3 Kas 2008
- CVE-2007-218228İzleyin
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP fil
OrtaCVSS 6,8Kavram kanıtıEPSS %4maran · php forum24 Nis 2007
- CVE-2007-319818İzleyin
Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remo
OrtaCVSS 4,3Kavram kanıtıEPSS %2maran · php blog12 Haz 2007