pbootcms kayıtları
pbootcms üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %5,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2022-32417İstismar yok | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.pbootcms · pbootcms · CWE-94 | Kritik9,8 | — | %35,6 | 14 Tem 2022 |
40Planlayın | CVE-2018-19595İstismar yok | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an pbootcms · pbootcms · CWE-94 | Kritik9,8 | — | %3,9 | 27 Kas 2018 |
40Planlayın | CVE-2020-23580İstismar yok | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.pbootcms · pbootcms | Kritik9,8 | — | %2,5 | 8 Tem 2021 |
40Planlayın | CVE-2023-39834İstismar yok | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.pbootcms · pbootcms · CWE-77 | Kritik9,8 | — | %2,1 | 24 Ağu 2023 |
40Planlayın | CVE-2018-16357İstismar yok | An issue was discovered in PbootCMS.pbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,8 | 2 Mar 2020 |
40Planlayın | CVE-2018-16356İstismar yok | An issue was discovered in PbootCMS.pbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,8 | 2 Mar 2020 |
39İzleyin | CVE-2018-18450İstismar yok | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POSTpbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,5 | 17 Eki 2018 |
39İzleyin | CVE-2018-10133İstismar yok | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabpbootcms · pbootcms · CWE-94 | Kritik9,8 | — | %1,4 | 16 Nis 2018 |
39İzleyin | CVE-2021-37497İstismar yok | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.pbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,2 | 3 Şub 2023 |
39İzleyin | CVE-2018-19893İstismar yok | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.pbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,1 | 5 Ara 2018 |
39İzleyin | CVE-2018-11369İstismar yok | An issue was discovered in PbootCMS v1.0.9.pbootcms · pbootcms · CWE-89 | Kritik9,8 | — | %1,1 | 22 May 2018 |
35İzleyin | CVE-2018-11018İstismar yok | An issue was discovered in PbootCMS v1.0.7.pbootcms · pbootcms · CWE-352 | Yüksek8,8 | — | %0,6 | 13 May 2018 |
35İzleyin | CVE-2020-20971İstismar yok | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.pbootcms · pbootcms · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Haz 2022 |
35İzleyin | CVE-2018-10132İstismar yok | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontenpbootcms · pbootcms · CWE-352 | Yüksek8,8 | — | %0,5 | 16 Nis 2018 |
35İzleyin | CVE-2025-46109İstismar yok | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET requpbootcms · pbootcms · CWE-89 | Yüksek8,8 | — | %0,4 | 18 Haz 2025 |
32İzleyin | CVE-2018-18211İstismar yok | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.pbootcms · pbootcms · CWE-89 | Yüksek8,1 | — | %0,9 | 10 Eki 2018 |
30İzleyin | CVE-2021-28245İstismar yok | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information throupbootcms · pbootcms · CWE-89 | Yüksek7,5 | — | %1,1 | 31 Mar 2021 |
30İzleyin | CVE-2023-50082İstismar yok | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via sessiopbootcms · pbootcms | Yüksek7,5 | — | %0,6 | 4 Oca 2024 |
28İzleyin | CVE-2018-19053İstismar yok | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statempbootcms · pbootcms · CWE-94 | Yüksek7,2 | — | %1,4 | 7 Kas 2018 |
28İzleyin | CVE-2019-8422İstismar yok | A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.phppbootcms · pbootcms · CWE-89 | Yüksek7,2 | — | %1,3 | 17 Şub 2019 |
26İzleyin | CVE-2020-22535İstismar yok | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.pbootcms · pbootcms · CWE-668 | Orta6,5 | — | %0,8 | 9 Tem 2021 |
26İzleyin | CVE-2019-7570İstismar yok | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.pbootcms · pbootcms · CWE-352 | Orta6,5 | — | %0,5 | 7 Şub 2019 |
26İzleyin | CVE-2020-17901İstismar yok | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.pbootcms · pbootcms · CWE-352 | Orta6,5 | — | %0,4 | 30 Kas 2020 |
24İzleyin | CVE-2024-1018İstismar yok | PbootCMS cross site scriptingpbootcms · pbootcms · CWE-79 | Orta6,1 | — | %0,5 | 29 Oca 2024 |
24İzleyin | CVE-2024-42930İstismar yok | PbootCMS 3.2.8 is vulnerable to URL Redirect.pbootcms · pbootcms · CWE-601 | Orta6,1 | — | %0,3 | 28 Eki 2024 |
- CVE-2022-3241750Planlayın
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
KritikCVSS 9,8İstismar yokEPSS %36pbootcms · pbootcms14 Tem 2022
- CVE-2018-1959540Planlayın
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an
KritikCVSS 9,8İstismar yokEPSS %4pbootcms · pbootcms27 Kas 2018
- CVE-2020-2358040Planlayın
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
KritikCVSS 9,8İstismar yokEPSS %2pbootcms · pbootcms8 Tem 2021
- CVE-2023-3983440Planlayın
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
KritikCVSS 9,8İstismar yokEPSS %2pbootcms · pbootcms24 Ağu 2023
- CVE-2018-1635740Planlayın
An issue was discovered in PbootCMS.
KritikCVSS 9,8İstismar yokEPSS %2pbootcms · pbootcms2 Mar 2020
- CVE-2018-1635640Planlayın
An issue was discovered in PbootCMS.
KritikCVSS 9,8İstismar yokEPSS %2pbootcms · pbootcms2 Mar 2020
- CVE-2018-1845039İzleyin
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST
KritikCVSS 9,8İstismar yokEPSS %2pbootcms · pbootcms17 Eki 2018
- CVE-2018-1013339İzleyin
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLab
KritikCVSS 9,8İstismar yokEPSS %1pbootcms · pbootcms16 Nis 2018
- CVE-2021-3749739İzleyin
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
KritikCVSS 9,8İstismar yokEPSS %1pbootcms · pbootcms3 Şub 2023
- CVE-2018-1989339İzleyin
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
KritikCVSS 9,8İstismar yokEPSS %1pbootcms · pbootcms5 Ara 2018
- CVE-2018-1136939İzleyin
An issue was discovered in PbootCMS v1.0.9.
KritikCVSS 9,8İstismar yokEPSS %1pbootcms · pbootcms22 May 2018
- CVE-2018-1101835İzleyin
An issue was discovered in PbootCMS v1.0.7.
YüksekCVSS 8,8İstismar yokEPSS %1pbootcms · pbootcms13 May 2018
- CVE-2020-2097135İzleyin
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
YüksekCVSS 8,8İstismar yokEPSS %1pbootcms · pbootcms2 Haz 2022
- CVE-2018-1013235İzleyin
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the reconten
YüksekCVSS 8,8İstismar yokEPSS %1pbootcms · pbootcms16 Nis 2018
- CVE-2025-4610935İzleyin
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET requ
YüksekCVSS 8,8İstismar yokEPSS %0pbootcms · pbootcms18 Haz 2025
- CVE-2018-1821132İzleyin
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
YüksekCVSS 8,1İstismar yokEPSS %1pbootcms · pbootcms10 Eki 2018
- CVE-2021-2824530İzleyin
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information throu
YüksekCVSS 7,5İstismar yokEPSS %1pbootcms · pbootcms31 Mar 2021
- CVE-2023-5008230İzleyin
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via sessio
YüksekCVSS 7,5İstismar yokEPSS %1pbootcms · pbootcms4 Oca 2024
- CVE-2018-1905328İzleyin
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statem
YüksekCVSS 7,2İstismar yokEPSS %1pbootcms · pbootcms7 Kas 2018
- CVE-2019-842228İzleyin
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php
YüksekCVSS 7,2İstismar yokEPSS %1pbootcms · pbootcms17 Şub 2019
- CVE-2020-2253526İzleyin
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
OrtaCVSS 6,5İstismar yokEPSS %1pbootcms · pbootcms9 Tem 2021
- CVE-2019-757026İzleyin
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
OrtaCVSS 6,5İstismar yokEPSS %1pbootcms · pbootcms7 Şub 2019
- CVE-2020-1790126İzleyin
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
OrtaCVSS 6,5İstismar yokEPSS %0pbootcms · pbootcms30 Kas 2020
- CVE-2024-101824İzleyin
PbootCMS cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1pbootcms · pbootcms29 Oca 2024
- CVE-2024-4293024İzleyin
PbootCMS 3.2.8 is vulnerable to URL Redirect.
OrtaCVSS 6,1İstismar yokEPSS %0pbootcms · pbootcms28 Eki 2024