papoo kayıtları
papoo üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2021-29054İstismar yok | Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface.papoo · papoo · CWE-352 | Yüksek8,8 | — | %0,8 | 13 Nis 2021 |
31İzleyin | CVE-2006-3572Kavram kanıtı | SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the papoo · papoo | Yüksek7,5 | — | %2,0 | 12 Tem 2006 |
30İzleyin | CVE-2005-4478Kavram kanıtı | Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuipapoo · papoo · CWE-89 | Yüksek7,5 | — | %1,3 | 22 Ara 2005 |
30İzleyin | CVE-2008-3724İstismar yok | SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl papoo · papoo · CWE-89 | Yüksek7,5 | — | %1,3 | 20 Ağu 2008 |
30İzleyin | CVE-2007-3453İstismar yok | SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid papoo · papoo | Yüksek7,5 | — | %1,3 | 26 Haz 2007 |
30İzleyin | CVE-2007-2320Kavram kanıtı | SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuipapoo · papoo | Yüksek7,5 | — | %1,2 | 26 Nis 2007 |
28İzleyin | CVE-2007-3494İstismar yok | Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote papoo · papoo | Orta6,8 | — | %2,1 | 29 Haz 2007 |
25İzleyin | CVE-2006-1766İstismar yok | Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands viapapoo · papoo | Orta6,4 | — | %1,0 | 13 Nis 2006 |
21İzleyin | CVE-2009-0735Kavram kanıtı | Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc ipapoo · papoo · CWE-22 | Orta5,1 | — | %2,2 | 25 Şub 2009 |
18İzleyin | CVE-2014-9522Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web scrippapoo · cms papoo light · CWE-79 | Orta4,3 | — | %3,5 | 5 Oca 2015 |
17İzleyin | CVE-2006-0569İstismar yok | Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web scriptpapoo · papoo | Orta4,3 | — | %1,2 | 7 Şub 2006 |
15İzleyin | CVE-2007-3269İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web scriptpapoo · papoo cms light | Düşük3,5 | — | %1,8 | 19 Haz 2007 |
11İzleyin | CVE-2006-3571Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrapapoo · papoo · CWE-79 | Düşük2,6 | — | %2,4 | 12 Tem 2006 |
11İzleyin | CVE-2006-1918Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menpapoo · papoo · CWE-79 | Düşük2,6 | — | %1,7 | 20 Nis 2006 |
- CVE-2021-2905435İzleyin
Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface.
YüksekCVSS 8,8İstismar yokEPSS %1papoo · papoo13 Nis 2021
- CVE-2006-357231İzleyin
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %2papoo · papoo12 Tem 2006
- CVE-2005-447830İzleyin
Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menui
YüksekCVSS 7,5Kavram kanıtıEPSS %1papoo · papoo22 Ara 2005
- CVE-2008-372430İzleyin
SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl
YüksekCVSS 7,5İstismar yokEPSS %1papoo · papoo20 Ağu 2008
- CVE-2007-345330İzleyin
SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid
YüksekCVSS 7,5İstismar yokEPSS %1papoo · papoo26 Haz 2007
- CVE-2007-232030İzleyin
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menui
YüksekCVSS 7,5Kavram kanıtıEPSS %1papoo · papoo26 Nis 2007
- CVE-2007-349428İzleyin
Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote
OrtaCVSS 6,8İstismar yokEPSS %2papoo · papoo29 Haz 2007
- CVE-2006-176625İzleyin
Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via
OrtaCVSS 6,4İstismar yokEPSS %1papoo · papoo13 Nis 2006
- CVE-2009-073521İzleyin
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc i
OrtaCVSS 5,1Kavram kanıtıEPSS %2papoo · papoo25 Şub 2009
- CVE-2014-952218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web scrip
OrtaCVSS 4,3Kavram kanıtıEPSS %4papoo · cms papoo light5 Oca 2015
- CVE-2006-056917İzleyin
Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1papoo · papoo7 Şub 2006
- CVE-2007-326915İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script
DüşükCVSS 3,5İstismar yokEPSS %2papoo · papoo cms light19 Haz 2007
- CVE-2006-357111İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitra
DüşükCVSS 2,6Kavram kanıtıEPSS %2papoo · papoo12 Tem 2006
- CVE-2006-191811İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the men
DüşükCVSS 2,6Kavram kanıtıEPSS %2papoo · papoo20 Nis 2006