phpgedview kayıtları
phpgedview üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %11,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2004-0030Kavram kanıtı | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 alphpgedview · phpgedview · CWE-829 | Kritik9,8 | — | %7,3 | 20 Oca 2004 |
41Planlayın | CVE-2008-2064İstismar yok | Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flawphpgedview · phpgedview | Kritik10,0 | — | %1,9 | 2 May 2008 |
32İzleyin | CVE-2004-0128Kavram kanıtı | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execphpgedview · phpgedview | Yüksek7,5 | — | %8,3 | 3 Mar 2004 |
32İzleyin | CVE-2005-4468Kavram kanıtı | PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary codphpgedview · phpgedview | Yüksek7,5 | — | %7,8 | 21 Ara 2005 |
31İzleyin | CVE-2005-4469İstismar yok | Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code vphpgedview · phpgedview | Yüksek7,5 | — | %2,7 | 21 Ara 2005 |
31İzleyin | CVE-2004-0127İstismar yok | Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary filesphpgedview · phpgedview | Yüksek7,5 | — | %2,2 | 3 Mar 2004 |
31İzleyin | CVE-2004-0065İstismar yok | Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2phpgedview · phpgedview | Yüksek7,5 | — | %1,9 | 17 Şub 2004 |
30İzleyin | CVE-2004-0031İstismar yok | PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconphpgedview · phpgedview | Yüksek7,5 | — | %1,5 | 20 Oca 2004 |
29İzleyin | CVE-2011-0405Kavram kanıtı | Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows rphpgedview · phpgedview · CWE-22 | Orta6,8 | — | %6,1 | 10 Oca 2011 |
28İzleyin | CVE-2004-0032Kavram kanıtı | Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script viphpgedview · phpgedview | Orta6,8 | — | %1,8 | 20 Oca 2004 |
21İzleyin | CVE-2005-4467Kavram kanıtı | Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrarphpgedview · phpgedview | Orta5,0 | — | %4,7 | 21 Ara 2005 |
21İzleyin | CVE-2004-0033Kavram kanıtı | admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.phpgedview · phpgedview | Orta5,0 | — | %2,8 | 20 Oca 2004 |
20İzleyin | CVE-2004-0130İstismar yok | login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does phpgedview · phpgedview | Orta5,0 | — | %1,5 | 3 Mar 2004 |
20İzleyin | CVE-2004-0066İstismar yok | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (phpgedview · phpgedview | Orta5,0 | — | %1,4 | 17 Şub 2004 |
20İzleyin | CVE-2011-3778İstismar yok | PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installationphpgedview · phpgedview · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
18İzleyin | CVE-2004-0067Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script phpgedview · phpgedview · CWE-79 | Orta4,3 | — | %3,1 | 17 Şub 2004 |
17İzleyin | CVE-2007-5051İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via thphpgedview · phpgedview · CWE-79 | Orta4,3 | — | %1,1 | 23 Eyl 2007 |
- CVE-2004-003041Planlayın
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al
KritikCVSS 9,8Kavram kanıtıEPSS %7phpgedview · phpgedview20 Oca 2004
- CVE-2008-206441Planlayın
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw
KritikCVSS 10,0İstismar yokEPSS %2phpgedview · phpgedview2 May 2008
- CVE-2004-012832İzleyin
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to exec
YüksekCVSS 7,5Kavram kanıtıEPSS %8phpgedview · phpgedview3 Mar 2004
- CVE-2005-446832İzleyin
PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary cod
YüksekCVSS 7,5Kavram kanıtıEPSS %8phpgedview · phpgedview21 Ara 2005
- CVE-2005-446931İzleyin
Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code v
YüksekCVSS 7,5İstismar yokEPSS %3phpgedview · phpgedview21 Ara 2005
- CVE-2004-012731İzleyin
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files
YüksekCVSS 7,5İstismar yokEPSS %2phpgedview · phpgedview3 Mar 2004
- CVE-2004-006531İzleyin
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2
YüksekCVSS 7,5İstismar yokEPSS %2phpgedview · phpgedview17 Şub 2004
- CVE-2004-003130İzleyin
PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editcon
YüksekCVSS 7,5İstismar yokEPSS %2phpgedview · phpgedview20 Oca 2004
- CVE-2011-040529İzleyin
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows r
OrtaCVSS 6,8Kavram kanıtıEPSS %6phpgedview · phpgedview10 Oca 2011
- CVE-2004-003228İzleyin
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script vi
OrtaCVSS 6,8Kavram kanıtıEPSS %2phpgedview · phpgedview20 Oca 2004
- CVE-2005-446721İzleyin
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrar
OrtaCVSS 5,0Kavram kanıtıEPSS %5phpgedview · phpgedview21 Ara 2005
- CVE-2004-003321İzleyin
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.
OrtaCVSS 5,0Kavram kanıtıEPSS %3phpgedview · phpgedview20 Oca 2004
- CVE-2004-013020İzleyin
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does
OrtaCVSS 5,0İstismar yokEPSS %2phpgedview · phpgedview3 Mar 2004
- CVE-2004-006620İzleyin
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (
OrtaCVSS 5,0İstismar yokEPSS %1phpgedview · phpgedview17 Şub 2004
- CVE-2011-377820İzleyin
PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1phpgedview · phpgedview23 Eyl 2011
- CVE-2004-006718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script
OrtaCVSS 4,3Kavram kanıtıEPSS %3phpgedview · phpgedview17 Şub 2004
- CVE-2007-505117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via th
OrtaCVSS 4,3İstismar yokEPSS %1phpgedview · phpgedview23 Eyl 2007