vwar kayıtları
vwar üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-189 Numeric Errors1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2006-1747Kavram kanıtı | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vvwar · virtual war | Yüksek7,5 | — | %4,0 | 12 Nis 2006 |
31İzleyin | CVE-2007-4605Kavram kanıtı | PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute avwar · virtual war · CWE-94 | Yüksek7,5 | — | %2,1 | 30 Ağu 2007 |
31İzleyin | CVE-2006-1636İstismar yok | PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP codvwar · virtual war · CWE-94 | Yüksek7,5 | — | %2,1 | 6 Nis 2006 |
31İzleyin | CVE-2006-4010Kavram kanıtı | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands viavwar · virtual war · CWE-89 | Yüksek7,5 | — | %1,8 | 7 Ağu 2006 |
31İzleyin | CVE-2006-3139İstismar yok | Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQvwar · virtual war · CWE-89 | Yüksek7,5 | — | %1,8 | 22 Haz 2006 |
30İzleyin | CVE-2006-4142Kavram kanıtı | SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQLvwar · virtual war | Yüksek7,5 | — | %1,3 | 14 Ağu 2006 |
30İzleyin | CVE-2006-4141İstismar yok | SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vivwar · virtual war | Yüksek7,5 | — | %1,2 | 14 Ağu 2006 |
30İzleyin | CVE-2007-2312Kavram kanıtı | Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary Svwar · virtual war | Yüksek7,5 | — | %1,2 | 26 Nis 2007 |
30İzleyin | CVE-2010-5063Kavram kanıtı | SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via vwar · virtual war · CWE-89 | Yüksek7,5 | — | %1,1 | 8 Eki 2012 |
30İzleyin | CVE-2008-0753Kavram kanıtı | SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the montvwar · virtual war · CWE-89 | Yüksek7,5 | — | %1,0 | 13 Şub 2008 |
27İzleyin | CVE-2010-5067İstismar yok | Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackervwar · virtual war · CWE-255 | Orta6,8 | — | %1,3 | 8 Eki 2012 |
27İzleyin | CVE-2005-4748İstismar yok | PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute vwar · virtual war | Orta6,8 | — | %1,3 | 31 Ara 2005 |
21İzleyin | CVE-2006-1503İstismar yok | PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackervwar · virtual war · CWE-94 | Orta5,1 | — | %2,0 | 29 Mar 2006 |
20İzleyin | CVE-2006-2091İstismar yok | admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_rootvwar · virtual war | Orta5,0 | — | %1,4 | 29 Nis 2006 |
20İzleyin | CVE-2010-5065İstismar yok | popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifivwar · virtual war · CWE-264 | Orta5,0 | — | %1,4 | 8 Eki 2012 |
20İzleyin | CVE-2010-5279İstismar yok | article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integervwar · virtual war · CWE-189 | Orta5,0 | — | %1,3 | 8 Eki 2012 |
20İzleyin | CVE-2011-3813İstismar yok | Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals tvwar · virtual war · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
18İzleyin | CVE-2006-4009Kavram kanıtı | Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web vwar · virtual war | Orta4,3 | — | %1,7 | 7 Ağu 2006 |
17İzleyin | CVE-2010-5066İstismar yok | The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to selectvwar · virtual war · CWE-310 | Orta4,3 | — | %1,2 | 8 Eki 2012 |
17İzleyin | CVE-2006-4224İstismar yok | Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitraryvwar · virtual war | Orta4,3 | — | %1,2 | 18 Ağu 2006 |
17İzleyin | CVE-2007-2306İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globavwar · virtual war | Orta4,3 | — | %1,1 | 26 Nis 2007 |
17İzleyin | CVE-2010-5064İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web scriptvwar · virtual war · CWE-79 | Orta4,3 | — | %1,0 | 8 Eki 2012 |
- CVE-2006-174731İzleyin
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the v
YüksekCVSS 7,5Kavram kanıtıEPSS %4vwar · virtual war12 Nis 2006
- CVE-2007-460531İzleyin
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %2vwar · virtual war30 Ağu 2007
- CVE-2006-163631İzleyin
PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP cod
YüksekCVSS 7,5İstismar yokEPSS %2vwar · virtual war6 Nis 2006
- CVE-2006-401031İzleyin
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %2vwar · virtual war7 Ağu 2006
- CVE-2006-313931İzleyin
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQ
YüksekCVSS 7,5İstismar yokEPSS %2vwar · virtual war22 Haz 2006
- CVE-2006-414230İzleyin
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL
YüksekCVSS 7,5Kavram kanıtıEPSS %1vwar · virtual war14 Ağu 2006
- CVE-2006-414130İzleyin
SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %1vwar · virtual war14 Ağu 2006
- CVE-2007-231230İzleyin
Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary S
YüksekCVSS 7,5Kavram kanıtıEPSS %1vwar · virtual war26 Nis 2007
- CVE-2010-506330İzleyin
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1vwar · virtual war8 Eki 2012
- CVE-2008-075330İzleyin
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the mont
YüksekCVSS 7,5Kavram kanıtıEPSS %1vwar · virtual war13 Şub 2008
- CVE-2010-506727İzleyin
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attacker
OrtaCVSS 6,8İstismar yokEPSS %1vwar · virtual war8 Eki 2012
- CVE-2005-474827İzleyin
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute
OrtaCVSS 6,8İstismar yokEPSS %1vwar · virtual war31 Ara 2005
- CVE-2006-150321İzleyin
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attacker
OrtaCVSS 5,1İstismar yokEPSS %2vwar · virtual war29 Mar 2006
- CVE-2006-209120İzleyin
admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root
OrtaCVSS 5,0İstismar yokEPSS %1vwar · virtual war29 Nis 2006
- CVE-2010-506520İzleyin
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifi
OrtaCVSS 5,0İstismar yokEPSS %1vwar · virtual war8 Eki 2012
- CVE-2010-527920İzleyin
article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer
OrtaCVSS 5,0İstismar yokEPSS %1vwar · virtual war8 Eki 2012
- CVE-2011-381320İzleyin
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals t
OrtaCVSS 5,0İstismar yokEPSS %1vwar · virtual war23 Eyl 2011
- CVE-2006-400918İzleyin
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2vwar · virtual war7 Ağu 2006
- CVE-2010-506617İzleyin
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select
OrtaCVSS 4,3İstismar yokEPSS %1vwar · virtual war8 Eki 2012
- CVE-2006-422417İzleyin
Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary
OrtaCVSS 4,3İstismar yokEPSS %1vwar · virtual war18 Ağu 2006
- CVE-2007-230617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globa
OrtaCVSS 4,3İstismar yokEPSS %1vwar · virtual war26 Nis 2007
- CVE-2010-506417İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1vwar · virtual war8 Eki 2012