newsphp kayıtları
newsphp üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2004-2689İstismar yok | NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.newsphp · newsphp · CWE-264 | Kritik10,0 | — | %2,2 | 31 Ara 2004 |
35İzleyin | CVE-2004-2690İstismar yok | Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execnewsphp · newsphp | Yüksek8,5 | — | %2,4 | 31 Ara 2004 |
31İzleyin | CVE-2003-0754İstismar yok | nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, newsphp · newsphp | Yüksek7,5 | — | %2,3 | 20 Eki 2003 |
30İzleyin | CVE-2006-0413Kavram kanıtı | Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss,newsphp · newsphp · CWE-89 | Yüksek7,5 | — | %1,3 | 25 Oca 2006 |
30İzleyin | CVE-2006-3359Kavram kanıtı | Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via thnewsphp · newsphp | Yüksek7,5 | — | %1,1 | 6 Tem 2006 |
27İzleyin | CVE-2006-3358Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script onewsphp · newsphp | Orta6,8 | — | %1,6 | 6 Tem 2006 |
21İzleyin | CVE-2003-0753İstismar yok | nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_confnewsphp · newsphp | Orta5,0 | — | %2,0 | 20 Eki 2003 |
17İzleyin | CVE-2004-2688İstismar yok | Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_newsphp · newsphp · CWE-79 | Orta4,3 | — | %1,0 | 31 Ara 2004 |
- CVE-2004-268941Planlayın
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
KritikCVSS 10,0İstismar yokEPSS %2newsphp · newsphp31 Ara 2004
- CVE-2004-269035İzleyin
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and exec
YüksekCVSS 8,5İstismar yokEPSS %2newsphp · newsphp31 Ara 2004
- CVE-2003-075431İzleyin
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array,
YüksekCVSS 7,5İstismar yokEPSS %2newsphp · newsphp20 Eki 2003
- CVE-2006-041330İzleyin
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss,
YüksekCVSS 7,5Kavram kanıtıEPSS %1newsphp · newsphp25 Oca 2006
- CVE-2006-335930İzleyin
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via th
YüksekCVSS 7,5Kavram kanıtıEPSS %1newsphp · newsphp6 Tem 2006
- CVE-2006-335827İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script o
OrtaCVSS 6,8Kavram kanıtıEPSS %2newsphp · newsphp6 Tem 2006
- CVE-2003-075321İzleyin
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_conf
OrtaCVSS 5,0İstismar yokEPSS %2newsphp · newsphp20 Eki 2003
- CVE-2004-268817İzleyin
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_
OrtaCVSS 4,3İstismar yokEPSS %1newsphp · newsphp31 Ara 2004