php-stats kayıtları
php-stats üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2006-7173Kavram kanıtı | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP cphp-stats · php-stats | Kritik10,0 | — | %3,8 | 20 Mar 2007 |
41Planlayın | CVE-2006-1085İstismar yok | admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbiphp-stats · php-stats | Kritik10,0 | — | %3,5 | 8 Mar 2006 |
41Planlayın | CVE-2007-5452Kavram kanıtı | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands php-stats · php-stats · CWE-89 | Kritik10,0 | — | %2,9 | 14 Eki 2007 |
35İzleyin | CVE-2007-5453Kavram kanıtı | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing php-stats · php-stats · CWE-94 | Yüksek8,5 | — | %3,9 | 14 Eki 2007 |
31İzleyin | CVE-2006-7172Kavram kanıtı | Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitraryphp-stats · php-stats | Yüksek7,5 | — | %2,3 | 20 Mar 2007 |
31İzleyin | CVE-2006-1083İstismar yok | Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary php-stats · php-stats | Yüksek7,5 | — | %2,2 | 8 Mar 2006 |
30İzleyin | CVE-2006-1084İstismar yok | Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) thephp-stats · php-stats | Yüksek7,5 | — | %1,5 | 8 Mar 2006 |
27İzleyin | CVE-2006-1087İstismar yok | Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authentiphp-stats · php-stats | Orta6,5 | — | %1,8 | 8 Mar 2006 |
21İzleyin | CVE-2006-1088İstismar yok | PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, wphp-stats · php-stats | Orta5,0 | — | %1,8 | 8 Mar 2006 |
18İzleyin | CVE-2007-4334Kavram kanıtı | Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats | Orta4,3 | — | %1,8 | 14 Ağu 2007 |
17İzleyin | CVE-2007-4917Kavram kanıtı | Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTMLphp-stats · php-stats · CWE-79 | Orta4,3 | — | %1,5 | 17 Eyl 2007 |
17İzleyin | CVE-2008-6212Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats · CWE-79 | Orta4,3 | — | %1,5 | 19 Şub 2009 |
- CVE-2006-717341Planlayın
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP c
KritikCVSS 10,0Kavram kanıtıEPSS %4php-stats · php-stats20 Mar 2007
- CVE-2006-108541Planlayın
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbi
KritikCVSS 10,0İstismar yokEPSS %4php-stats · php-stats8 Mar 2006
- CVE-2007-545241Planlayın
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands
KritikCVSS 10,0Kavram kanıtıEPSS %3php-stats · php-stats14 Eki 2007
- CVE-2007-545335İzleyin
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing
YüksekCVSS 8,5Kavram kanıtıEPSS %4php-stats · php-stats14 Eki 2007
- CVE-2006-717231İzleyin
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %2php-stats · php-stats20 Mar 2007
- CVE-2006-108331İzleyin
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary
YüksekCVSS 7,5İstismar yokEPSS %2php-stats · php-stats8 Mar 2006
- CVE-2006-108430İzleyin
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the
YüksekCVSS 7,5İstismar yokEPSS %2php-stats · php-stats8 Mar 2006
- CVE-2006-108727İzleyin
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenti
OrtaCVSS 6,5İstismar yokEPSS %2php-stats · php-stats8 Mar 2006
- CVE-2006-108821İzleyin
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, w
OrtaCVSS 5,0İstismar yokEPSS %2php-stats · php-stats8 Mar 2006
- CVE-2007-433418İzleyin
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 4,3Kavram kanıtıEPSS %2php-stats · php-stats14 Ağu 2007
- CVE-2007-491717İzleyin
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %1php-stats · php-stats17 Eyl 2007
- CVE-2008-621217İzleyin
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 4,3Kavram kanıtıEPSS %1php-stats · php-stats19 Şub 2009