phpnews kayıtları
phpnews üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Saldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2006-7081Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include paramphpnews · phpnews | Yüksek7,5 | — | %2,7 | 2 Mar 2007 |
30İzleyin | CVE-2004-2474İstismar yok | SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriendphpnews · phpnews | Yüksek7,5 | — | %1,2 | 31 Ara 2004 |
30İzleyin | CVE-2005-2383Kavram kanıtı | SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter inphpnews · phpnews | Yüksek7,5 | — | %1,2 | 26 Tem 2005 |
30İzleyin | CVE-2005-2156İstismar yok | SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parametephpnews · phpnews | Yüksek7,5 | — | %1,1 | 6 Tem 2005 |
28İzleyin | CVE-2006-6356Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary wphpnews · phpnews | Orta6,8 | — | %2,0 | 6 Ara 2006 |
27İzleyin | CVE-2006-6357İstismar yok | Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary phpnews · phpnews | Orta6,8 | — | %1,1 | 6 Ara 2006 |
21İzleyin | CVE-2005-0632Kavram kanıtı | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP cophpnews · phpnews | Orta5,0 | — | %2,6 | 1 Mar 2005 |
- CVE-2006-708131İzleyin
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include param
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpnews · phpnews2 Mar 2007
- CVE-2004-247430İzleyin
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend
YüksekCVSS 7,5İstismar yokEPSS %1phpnews · phpnews31 Ara 2004
- CVE-2005-238330İzleyin
SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnews · phpnews26 Tem 2005
- CVE-2005-215630İzleyin
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext paramete
YüksekCVSS 7,5İstismar yokEPSS %1phpnews · phpnews6 Tem 2005
- CVE-2006-635628İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary w
OrtaCVSS 6,8Kavram kanıtıEPSS %2phpnews · phpnews6 Ara 2006
- CVE-2006-635727İzleyin
Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary
OrtaCVSS 6,8İstismar yokEPSS %1phpnews · phpnews6 Ara 2006
- CVE-2005-063221İzleyin
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP co
OrtaCVSS 5,0Kavram kanıtıEPSS %3phpnews · phpnews1 Mar 2005