phpauction kayıtları
phpauction üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2008-1416Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in phpauction · phpauction gpl · CWE-94 | Orta6,8 | — | %37,7 | 20 Mar 2008 |
31İzleyin | CVE-2008-7000Kavram kanıtı | PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in thphpauction · phpauction · CWE-94 | Yüksek7,5 | — | %2,1 | 19 Ağu 2009 |
30İzleyin | CVE-2008-2900Kavram kanıtı | SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.phpauction · phpauction · CWE-89 | Yüksek7,5 | — | %1,0 | 27 Haz 2008 |
20İzleyin | CVE-2008-6999İstismar yok | phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phphpauction · phpauction · CWE-200 | Orta5,0 | — | %1,3 | 19 Ağu 2009 |
- CVE-2008-141638İzleyin
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in
OrtaCVSS 6,8Kavram kanıtıEPSS %38phpauction · phpauction gpl20 Mar 2008
- CVE-2008-700031İzleyin
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in th
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpauction · phpauction19 Ağu 2009
- CVE-2008-290030İzleyin
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpauction · phpauction27 Haz 2008
- CVE-2008-699920İzleyin
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to ph
OrtaCVSS 5,0İstismar yokEPSS %1phpauction · phpauction19 Ağu 2009