phpwebsite kayıtları
phpwebsite üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2002-1135Kavram kanıtı | modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_pphpwebsite · phpwebsite | Yüksek7,5 | — | %6,6 | 4 Eki 2002 |
31İzleyin | CVE-2006-1819İstismar yok | Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includphpwebsite · phpwebsite | Yüksek7,5 | — | %3,9 | 18 Nis 2006 |
31İzleyin | CVE-2006-5234Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in thphpwebsite · phpwebsite | Yüksek7,5 | — | %2,8 | 10 Eki 2006 |
31İzleyin | CVE-2005-0565İstismar yok | The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to refphpwebsite · phpwebsite | Yüksek7,5 | — | %1,7 | 2 May 2005 |
31İzleyin | CVE-2003-0735Kavram kanıtı | SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,phpwebsite · phpwebsite | Yüksek7,5 | — | %1,7 | 20 Eki 2003 |
31İzleyin | CVE-2003-0738İstismar yok | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.phpwebsite · phpwebsite · CWE-134 | Yüksek7,8 | — | %1,5 | 20 Eki 2003 |
30İzleyin | CVE-2004-2322İstismar yok | SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrphpwebsite · phpwebsite | Yüksek7,5 | — | %1,5 | 31 Ara 2004 |
30İzleyin | CVE-2004-1654İstismar yok | SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commanphpwebsite · phpwebsite | Yüksek7,5 | — | %1,3 | 1 Eyl 2004 |
30İzleyin | CVE-2006-0973Kavram kanıtı | SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute aphpwebsite · phpwebsite | Yüksek7,5 | — | %1,3 | 3 Mar 2006 |
30İzleyin | CVE-2006-1330Kavram kanıtı | Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid pphpwebsite · phpwebsite · CWE-89 | Yüksek7,5 | — | %1,3 | 20 Mar 2006 |
30İzleyin | CVE-2005-4792Kavram kanıtı | SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arphpwebsite · phpwebsite | Yüksek7,5 | — | %1,1 | 31 Ara 2005 |
28İzleyin | CVE-2003-0736Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script vphpwebsite · phpwebsite | Orta6,8 | — | %2,7 | 20 Eki 2003 |
21İzleyin | CVE-2005-0572İstismar yok | index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parametephpwebsite · phpwebsite | Orta5,0 | — | %2,1 | 2 May 2005 |
20İzleyin | CVE-2004-1516İstismar yok | CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modifyphpwebsite · phpwebsite | Orta5,0 | — | %1,6 | 31 Ara 2004 |
20İzleyin | CVE-2003-0737İstismar yok | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, wphpwebsite · phpwebsite | Orta5,0 | — | %1,3 | 20 Eki 2003 |
18İzleyin | CVE-2004-1655Kavram kanıtı | Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML viphpwebsite · phpwebsite | Orta4,3 | — | %2,2 | 1 Eyl 2004 |
18İzleyin | CVE-2002-2178Kavram kanıtı | Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript phpwebsite · phpwebsite | Orta4,3 | — | %1,7 | 31 Ara 2002 |
18İzleyin | CVE-2008-0092Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote atphpwebsite · phpwebsite · CWE-79 | Orta4,3 | — | %1,7 | 3 Oca 2008 |
17İzleyin | CVE-2002-1807İstismar yok | Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript iphpwebsite · phpwebsite | Orta4,3 | — | %1,2 | 31 Ara 2002 |
17İzleyin | CVE-2011-4265İstismar yok | Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspephpwebsite · phpwebsite · CWE-79 | Orta4,3 | — | %0,8 | 8 Ara 2011 |
- CVE-2002-113532İzleyin
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_p
YüksekCVSS 7,5Kavram kanıtıEPSS %7phpwebsite · phpwebsite4 Eki 2002
- CVE-2006-181931İzleyin
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includ
YüksekCVSS 7,5İstismar yokEPSS %4phpwebsite · phpwebsite18 Nis 2006
- CVE-2006-523431İzleyin
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in th
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpwebsite · phpwebsite10 Eki 2006
- CVE-2005-056531İzleyin
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to ref
YüksekCVSS 7,5İstismar yokEPSS %2phpwebsite · phpwebsite2 May 2005
- CVE-2003-073531İzleyin
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpwebsite · phpwebsite20 Eki 2003
- CVE-2003-073831İzleyin
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
YüksekCVSS 7,8İstismar yokEPSS %1phpwebsite · phpwebsite20 Eki 2003
- CVE-2004-232230İzleyin
SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitr
YüksekCVSS 7,5İstismar yokEPSS %2phpwebsite · phpwebsite31 Ara 2004
- CVE-2004-165430İzleyin
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5İstismar yokEPSS %1phpwebsite · phpwebsite1 Eyl 2004
- CVE-2006-097330İzleyin
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpwebsite · phpwebsite3 Mar 2006
- CVE-2006-133030İzleyin
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid p
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpwebsite · phpwebsite20 Mar 2006
- CVE-2005-479230İzleyin
SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute ar
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpwebsite · phpwebsite31 Ara 2005
- CVE-2003-073628İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script v
OrtaCVSS 6,8Kavram kanıtıEPSS %3phpwebsite · phpwebsite20 Eki 2003
- CVE-2005-057221İzleyin
index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module paramete
OrtaCVSS 5,0İstismar yokEPSS %2phpwebsite · phpwebsite2 May 2005
- CVE-2004-151620İzleyin
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify
OrtaCVSS 5,0İstismar yokEPSS %2phpwebsite · phpwebsite31 Ara 2004
- CVE-2003-073720İzleyin
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, w
OrtaCVSS 5,0İstismar yokEPSS %1phpwebsite · phpwebsite20 Eki 2003
- CVE-2004-165518İzleyin
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpwebsite · phpwebsite1 Eyl 2004
- CVE-2002-217818İzleyin
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpwebsite · phpwebsite31 Ara 2002
- CVE-2008-009218İzleyin
Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote at
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpwebsite · phpwebsite3 Oca 2008
- CVE-2002-180717İzleyin
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript i
OrtaCVSS 4,3İstismar yokEPSS %1phpwebsite · phpwebsite31 Ara 2002
- CVE-2011-426517İzleyin
Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspe
OrtaCVSS 4,3İstismar yokEPSS %1phpwebsite · phpwebsite8 Ara 2011