pear kayıtları
pear üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %72,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG)1
- CWE-624 Executable Regular Expression Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-783 Operator Precedence Logic Error1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2009-4025İstismar yok | Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows repear · pear · CWE-78 | Kritik10,0 | — | %6,1 | 29 Kas 2009 |
42Planlayın | CVE-2009-4024İstismar yok | Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to epear · pear · CWE-94 | Kritik10,0 | — | %6,1 | 29 Kas 2009 |
40Planlayın | CVE-2017-5677İstismar yok | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.pear · html ajax | Kritik9,8 | — | %4,8 | 6 Şub 2017 |
40Planlayın | CVE-2005-4730İstismar yok | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nupear · text password | Kritik10,0 | — | %1,4 | 31 Ara 2005 |
37İzleyin | CVE-2026-25241İstismar yok | PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpointpear · pearweb · CWE-89 | Kritik9,3 | — | %0,4 | 3 Şub 2026 |
36İzleyin | CVE-2026-25237İstismar yok | PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emailspear · pearweb · CWE-624 | Kritik9,2 | — | %0,4 | 3 Şub 2026 |
36İzleyin | CVE-2026-25238İstismar yok | PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validationpear · pearweb · CWE-89 | Kritik9,2 | — | %0,3 | 3 Şub 2026 |
32İzleyin | CVE-2026-25235İstismar yok | PEAR Has a Predictable Verification Hash in Election Account Requestspear · pearweb · CWE-337 | Yüksek8,2 | — | %0,3 | 3 Şub 2026 |
32İzleyin | CVE-2026-25239İstismar yok | PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filenamepear · pearweb · CWE-89 | Yüksek8,2 | — | %0,2 | 3 Şub 2026 |
31İzleyin | CVE-2006-0868İstismar yok | Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4pear · xml rpc | Yüksek7,5 | — | %2,5 | 23 Şub 2006 |
31İzleyin | CVE-2009-4023İstismar yok | Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for pear · pear · CWE-94 | Yüksek7,5 | — | %2,4 | 29 Kas 2009 |
28İzleyin | CVE-2026-25233İstismar yok | PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bugpear · pearweb · CWE-783 | Yüksek7,1 | — | %0,3 | 3 Şub 2026 |
27İzleyin | CVE-2009-4111İstismar yok | Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remotpear · mail · CWE-94 | Orta6,8 | — | %1,6 | 29 Kas 2009 |
27İzleyin | CVE-2026-25240İstismar yok | PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filterpear · pearweb · CWE-89 | Orta6,9 | — | %0,3 | 3 Şub 2026 |
27İzleyin | CVE-2026-25236İstismar yok | PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitutionpear · pearweb · CWE-89 | Orta6,9 | — | %0,3 | 3 Şub 2026 |
26İzleyin | CVE-2006-0869Kavram kanıtı | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0pear · pear liveuser | Orta6,4 | — | %4,0 | 23 Şub 2006 |
21İzleyin | CVE-2006-0931İstismar yok | Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwritepear · pear archive tar · CWE-22 | Orta5,0 | — | %2,4 | 28 Şub 2006 |
21İzleyin | CVE-2006-0932İstismar yok | Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files pear · pear archive zip | Orta5,0 | — | %1,9 | 28 Şub 2006 |
21İzleyin | CVE-2022-24953İstismar yok | The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environmentpear · crypt gpg · CWE-88 | Orta5,3 | — | %0,9 | 17 Şub 2022 |
21İzleyin | CVE-2026-25234İstismar yok | PEAR is Vulnerable to SQL Injection in Category Deletionpear · pearweb · CWE-89 | Orta5,3 | — | %0,3 | 3 Şub 2026 |
20İzleyin | CVE-2007-3628İstismar yok | Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers tpear · structures datagrid datasource mdb2 | Orta5,0 | — | %1,0 | 9 Tem 2007 |
17İzleyin | CVE-2007-5934İstismar yok | The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contentspear · structures datagrid datasource mdb2 · CWE-200 | Orta4,3 | — | %1,6 | 13 Kas 2007 |
- CVE-2009-402542Planlayın
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows re
KritikCVSS 10,0İstismar yokEPSS %6pear · pear29 Kas 2009
- CVE-2009-402442Planlayın
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to e
KritikCVSS 10,0İstismar yokEPSS %6pear · pear29 Kas 2009
- CVE-2017-567740Planlayın
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.
KritikCVSS 9,8İstismar yokEPSS %5pear · html ajax6 Şub 2017
- CVE-2005-473040Planlayın
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nu
KritikCVSS 10,0İstismar yokEPSS %1pear · text password31 Ara 2005
- CVE-2026-2524137İzleyin
PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpoint
KritikCVSS 9,3İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2026-2523736İzleyin
PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails
KritikCVSS 9,2İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2026-2523836İzleyin
PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation
KritikCVSS 9,2İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2026-2523532İzleyin
PEAR Has a Predictable Verification Hash in Election Account Requests
YüksekCVSS 8,2İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2026-2523932İzleyin
PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filename
YüksekCVSS 8,2İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2006-086831İzleyin
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4
YüksekCVSS 7,5İstismar yokEPSS %3pear · xml rpc23 Şub 2006
- CVE-2009-402331İzleyin
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for
YüksekCVSS 7,5İstismar yokEPSS %2pear · pear29 Kas 2009
- CVE-2026-2523328İzleyin
PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
YüksekCVSS 7,1İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2009-411127İzleyin
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remot
OrtaCVSS 6,8İstismar yokEPSS %2pear · mail29 Kas 2009
- CVE-2026-2524027İzleyin
PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filter
OrtaCVSS 6,9İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2026-2523627İzleyin
PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitution
OrtaCVSS 6,9İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2006-086926İzleyin
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0
OrtaCVSS 6,4Kavram kanıtıEPSS %4pear · pear liveuser23 Şub 2006
- CVE-2006-093121İzleyin
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite
OrtaCVSS 5,0İstismar yokEPSS %2pear · pear archive tar28 Şub 2006
- CVE-2006-093221İzleyin
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files
OrtaCVSS 5,0İstismar yokEPSS %2pear · pear archive zip28 Şub 2006
- CVE-2022-2495321İzleyin
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environment
OrtaCVSS 5,3İstismar yokEPSS %1pear · crypt gpg17 Şub 2022
- CVE-2026-2523421İzleyin
PEAR is Vulnerable to SQL Injection in Category Deletion
OrtaCVSS 5,3İstismar yokEPSS %0pear · pearweb3 Şub 2026
- CVE-2007-362820İzleyin
Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers t
OrtaCVSS 5,0İstismar yokEPSS %1pear · structures datagrid datasource mdb29 Tem 2007
- CVE-2007-593417İzleyin
The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents
OrtaCVSS 4,3İstismar yokEPSS %2pear · structures datagrid datasource mdb213 Kas 2007