phpwind kayıtları
phpwind üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2006-7101Kavram kanıtı | SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Admiphpwind · phpwind | Yüksek7,5 | — | %1,0 | 3 Mar 2007 |
28İzleyin | CVE-2019-6691İstismar yok | phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup daphpwind · phpwind · CWE-89 | Yüksek7,2 | — | %1,1 | 23 Oca 2019 |
24İzleyin | CVE-2015-4134İstismar yok | Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishingphpwind · phpwind | Orta5,8 | — | %2,1 | 28 May 2015 |
24İzleyin | CVE-2019-13472İstismar yok | PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.phpwind · phpwind · CWE-79 | Orta6,1 | — | %0,8 | 9 Tem 2019 |
18İzleyin | CVE-2015-4135İstismar yok | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the uphpwind · phpwind · CWE-79 | Orta4,3 | — | %1,9 | 28 May 2015 |
- CVE-2006-710130İzleyin
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Admi
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpwind · phpwind3 Mar 2007
- CVE-2019-669128İzleyin
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup da
YüksekCVSS 7,2İstismar yokEPSS %1phpwind · phpwind23 Oca 2019
- CVE-2015-413424İzleyin
Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing
OrtaCVSS 5,8İstismar yokEPSS %2phpwind · phpwind28 May 2015
- CVE-2019-1347224İzleyin
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
OrtaCVSS 6,1İstismar yokEPSS %1phpwind · phpwind9 Tem 2019
- CVE-2015-413518İzleyin
Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the u
OrtaCVSS 4,3İstismar yokEPSS %2phpwind · phpwind28 May 2015