plogger kayıtları
plogger üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-254 7PK - Security Features1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2005-4573Kavram kanıtı | PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a plogger · plogger · CWE-94 | Yüksek7,5 | — | %11,7 | 29 Ara 2005 |
33İzleyin | CVE-2014-2223Kavram kanıtı | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to exeplogger · plogger · CWE-94 | Yüksek7,5 | — | %10,0 | 11 Eyl 2014 |
31İzleyin | CVE-2007-6587Kavram kanıtı | SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parplogger · plogger · CWE-89 | Yüksek7,5 | — | %3,4 | 28 Ara 2007 |
31İzleyin | CVE-2008-3563Kavram kanıtı | Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checkplogger · plogger · CWE-89 | Yüksek7,5 | — | %2,4 | 10 Ağu 2008 |
30İzleyin | CVE-2007-2277İstismar yok | Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.plogger · plogger · CWE-287 | Yüksek7,5 | — | %1,4 | 25 Nis 2007 |
30İzleyin | CVE-2012-5289İstismar yok | Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (plogger · plogger · CWE-89 | Yüksek7,5 | — | %1,3 | 4 Eki 2012 |
30İzleyin | CVE-2005-4246Kavram kanıtı | SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameterplogger · plogger · CWE-89 | Yüksek7,5 | — | %1,1 | 14 Ara 2005 |
30İzleyin | CVE-2006-2157İstismar yok | SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via theplogger · plogger · CWE-89 | Yüksek7,5 | — | %1,1 | 3 May 2006 |
20İzleyin | CVE-2014-2224İstismar yok | Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote atplogger · plogger · CWE-254 | Orta5,0 | — | %1,4 | 29 Ara 2014 |
18İzleyin | CVE-2005-4247Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script oplogger · plogger · CWE-79 | Orta4,3 | — | %1,7 | 14 Ara 2005 |
- CVE-2005-457334İzleyin
PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a
YüksekCVSS 7,5Kavram kanıtıEPSS %12plogger · plogger29 Ara 2005
- CVE-2014-222333İzleyin
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to exe
YüksekCVSS 7,5Kavram kanıtıEPSS %10plogger · plogger11 Eyl 2014
- CVE-2007-658731İzleyin
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id par
YüksekCVSS 7,5Kavram kanıtıEPSS %3plogger · plogger28 Ara 2007
- CVE-2008-356331İzleyin
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the check
YüksekCVSS 7,5Kavram kanıtıEPSS %2plogger · plogger10 Ağu 2008
- CVE-2007-227730İzleyin
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
YüksekCVSS 7,5İstismar yokEPSS %1plogger · plogger25 Nis 2007
- CVE-2012-528930İzleyin
Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (
YüksekCVSS 7,5İstismar yokEPSS %1plogger · plogger4 Eki 2012
- CVE-2005-424630İzleyin
SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %1plogger · plogger14 Ara 2005
- CVE-2006-215730İzleyin
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5İstismar yokEPSS %1plogger · plogger3 May 2006
- CVE-2014-222420İzleyin
Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote at
OrtaCVSS 5,0İstismar yokEPSS %1plogger · plogger29 Ara 2014
- CVE-2005-424718İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script o
OrtaCVSS 4,3Kavram kanıtıEPSS %2plogger · plogger14 Ara 2005