pixelpost kayıtları
pixelpost üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2009-4899İstismar yok | pixelpost 1.7.1 has SQL injectionpixelpost · pixelpost · CWE-89 | Kritik9,8 | — | %1,3 | 28 Eki 2019 |
35İzleyin | CVE-2010-3305İstismar yok | Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.pixelpost · pixelpost · CWE-352 | Yüksek8,8 | — | %1,0 | 12 Kas 2019 |
30İzleyin | CVE-2006-1104İstismar yok | Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) pixelpost · pixelpost | Yüksek7,5 | — | %1,5 | 9 Mar 2006 |
29İzleyin | CVE-2018-0604İstismar yok | Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.pixelpost · pixelpost | Yüksek7,2 | — | %1,8 | 26 Haz 2018 |
28İzleyin | CVE-2008-3365Kavram kanıtı | Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to ipixelpost · pixelpost · CWE-22 | Orta6,8 | — | %3,8 | 30 Tem 2008 |
28İzleyin | CVE-2008-0358Kavram kanıtı | SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id paramepixelpost · pixelpost · CWE-89 | Orta6,8 | — | %2,2 | 18 Oca 2008 |
28İzleyin | CVE-2018-0606İstismar yok | SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via pixelpost · pixelpost · CWE-89 | Yüksek7,2 | — | %1,1 | 26 Haz 2018 |
26İzleyin | CVE-2011-1100Kavram kanıtı | Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commapixelpost · pixelpost · CWE-89 | Orta6,5 | — | %1,3 | 25 Şub 2011 |
24İzleyin | CVE-2009-4900İstismar yok | pixelpost 1.7.1 has XSSpixelpost · pixelpost · CWE-79 | Orta6,1 | — | %1,0 | 28 Eki 2019 |
24İzleyin | CVE-2018-0605İstismar yok | Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecpixelpost · pixelpost · CWE-79 | Orta6,1 | — | %0,8 | 26 Haz 2018 |
21İzleyin | CVE-2006-1105İstismar yok | Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, wpixelpost · pixelpost | Orta5,0 | — | %1,7 | 9 Mar 2006 |
20İzleyin | CVE-2006-2890İstismar yok | Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct otherpixelpost · pixelpost | Orta5,1 | — | %1,5 | 7 Haz 2006 |
20İzleyin | CVE-2011-3792İstismar yok | Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pixelpost · pixelpost · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
20İzleyin | CVE-2006-2889Kavram kanıtı | Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commanpixelpost · pixelpost | Orta5,1 | — | %1,1 | 7 Haz 2006 |
18İzleyin | CVE-2006-0409Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script orpixelpost · photoblog | Orta4,3 | — | %2,0 | 24 Oca 2006 |
18İzleyin | CVE-2006-1106İstismar yok | Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML pixelpost · pixelpost | Orta4,3 | — | %2,0 | 9 Mar 2006 |
11İzleyin | CVE-2006-2891İstismar yok | Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary Hpixelpost · pixelpost | Düşük2,6 | — | %1,9 | 7 Haz 2006 |
- CVE-2009-489939İzleyin
pixelpost 1.7.1 has SQL injection
KritikCVSS 9,8İstismar yokEPSS %1pixelpost · pixelpost28 Eki 2019
- CVE-2010-330535İzleyin
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
YüksekCVSS 8,8İstismar yokEPSS %1pixelpost · pixelpost12 Kas 2019
- CVE-2006-110430İzleyin
Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1)
YüksekCVSS 7,5İstismar yokEPSS %2pixelpost · pixelpost9 Mar 2006
- CVE-2018-060429İzleyin
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
YüksekCVSS 7,2İstismar yokEPSS %2pixelpost · pixelpost26 Haz 2018
- CVE-2008-336528İzleyin
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to i
OrtaCVSS 6,8Kavram kanıtıEPSS %4pixelpost · pixelpost30 Tem 2008
- CVE-2008-035828İzleyin
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parame
OrtaCVSS 6,8Kavram kanıtıEPSS %2pixelpost · pixelpost18 Oca 2008
- CVE-2018-060628İzleyin
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via
YüksekCVSS 7,2İstismar yokEPSS %1pixelpost · pixelpost26 Haz 2018
- CVE-2011-110026İzleyin
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL comma
OrtaCVSS 6,5Kavram kanıtıEPSS %1pixelpost · pixelpost25 Şub 2011
- CVE-2009-490024İzleyin
pixelpost 1.7.1 has XSS
OrtaCVSS 6,1İstismar yokEPSS %1pixelpost · pixelpost28 Eki 2019
- CVE-2018-060524İzleyin
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspec
OrtaCVSS 6,1İstismar yokEPSS %1pixelpost · pixelpost26 Haz 2018
- CVE-2006-110521İzleyin
Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, w
OrtaCVSS 5,0İstismar yokEPSS %2pixelpost · pixelpost9 Mar 2006
- CVE-2006-289020İzleyin
Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct other
OrtaCVSS 5,1İstismar yokEPSS %1pixelpost · pixelpost7 Haz 2006
- CVE-2011-379220İzleyin
Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1pixelpost · pixelpost23 Eyl 2011
- CVE-2006-288920İzleyin
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL comman
OrtaCVSS 5,1Kavram kanıtıEPSS %1pixelpost · pixelpost7 Haz 2006
- CVE-2006-040918İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %2pixelpost · photoblog24 Oca 2006
- CVE-2006-110618İzleyin
Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3İstismar yokEPSS %2pixelpost · pixelpost9 Mar 2006
- CVE-2006-289111İzleyin
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary H
DüşükCVSS 2,6İstismar yokEPSS %2pixelpost · pixelpost7 Haz 2006