web-app.org kayıtları
web-app.org üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-16 Configuration1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2005-0927İstismar yok | Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacweb-app.org · webapp | Kritik10,0 | — | %1,6 | 2 May 2005 |
33İzleyin | CVE-2005-1628Kavram kanıtı | apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharactersweb-app.org · webapp · CWE-20 | Yüksek7,5 | — | %10,6 | 17 May 2005 |
31İzleyin | CVE-2007-3242İstismar yok | The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allowsweb-app.net · webapp · CWE-264 | Yüksek7,5 | — | %2,1 | 14 Haz 2007 |
30İzleyin | CVE-2007-1188İstismar yok | WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has uweb-app.org · webapp | Yüksek7,5 | — | %1,5 | 2 Mar 2007 |
30İzleyin | CVE-2007-1183İstismar yok | WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attacweb-app.org · webapp | Yüksek7,5 | — | %1,5 | 2 Mar 2007 |
30İzleyin | CVE-2007-1178İstismar yok | WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,web-app.org · webapp | Yüksek7,5 | — | %1,4 | 2 Mar 2007 |
30İzleyin | CVE-2007-1259İstismar yok | Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.web-app.org · webapp | Yüksek7,5 | — | %1,3 | 3 Mar 2007 |
30İzleyin | CVE-2007-3424İstismar yok | The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory namweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
30İzleyin | CVE-2007-3419İstismar yok | The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) laweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
30İzleyin | CVE-2007-3420İstismar yok | The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not cweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
30İzleyin | CVE-2007-3421İstismar yok | The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
30İzleyin | CVE-2007-3422İstismar yok | The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-priweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
30İzleyin | CVE-2007-3423İstismar yok | cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .daweb-app.org · webapp | Yüksek7,5 | — | %1,1 | 26 Haz 2007 |
27İzleyin | CVE-2007-1489İstismar yok | Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin accesweb-app.org · webapp · CWE-352 | Orta6,8 | — | %0,7 | 16 Mar 2007 |
26İzleyin | CVE-2007-3418İstismar yok | The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction web-app.org · webapp | Orta6,5 | — | %1,1 | 26 Haz 2007 |
25İzleyin | CVE-2007-1827İstismar yok | Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corruweb-app.org · webapp | Orta6,0 | — | %1,9 | 2 Nis 2007 |
25İzleyin | CVE-2007-1182İstismar yok | WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.web-app.org · webapp | Orta6,4 | — | %1,1 | 2 Mar 2007 |
24İzleyin | CVE-2007-1831İstismar yok | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.web-app.org · webapp | Orta6,0 | — | %1,1 | 2 Nis 2007 |
23İzleyin | CVE-2007-1177İstismar yok | WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Pweb-app.org · webapp | Orta5,8 | — | %1,1 | 2 Mar 2007 |
22İzleyin | CVE-2004-1742Kavram kanıtı | Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..web-app.org · webapp | Orta5,0 | — | %7,2 | 24 Ağu 2004 |
22İzleyin | CVE-2007-1187İstismar yok | WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archiveweb-app.org · webapp | Orta5,5 | — | %1,2 | 2 Mar 2007 |
20İzleyin | CVE-2007-1832İstismar yok | web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percweb-app.org · webapp | Orta5,0 | — | %1,2 | 2 Nis 2007 |
20İzleyin | CVE-2007-1181İstismar yok | WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack veweb-app.org · webapp | Orta5,0 | — | %1,1 | 2 Mar 2007 |
20İzleyin | CVE-2007-1186İstismar yok | WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.web-app.org · webapp | Orta5,0 | — | %1,1 | 2 Mar 2007 |
20İzleyin | CVE-2007-1185İstismar yok | The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown iweb-app.org · webapp | Orta5,0 | — | %1,1 | 2 Mar 2007 |
- CVE-2005-092740Planlayın
Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharac
KritikCVSS 10,0İstismar yokEPSS %2web-app.org · webapp2 May 2005
- CVE-2005-162833İzleyin
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters
YüksekCVSS 7,5Kavram kanıtıEPSS %11web-app.org · webapp17 May 2005
- CVE-2007-324231İzleyin
The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows
YüksekCVSS 7,5İstismar yokEPSS %2web-app.net · webapp14 Haz 2007
- CVE-2007-118830İzleyin
WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has u
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-118330İzleyin
WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attac
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-117830İzleyin
WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration,
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-125930İzleyin
Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp3 Mar 2007
- CVE-2007-342430İzleyin
The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory nam
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-341930İzleyin
The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) la
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-342030İzleyin
The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not c
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-342130İzleyin
The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gall
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-342230İzleyin
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-pri
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-342330İzleyin
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .da
YüksekCVSS 7,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-148927İzleyin
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin acces
OrtaCVSS 6,8İstismar yokEPSS %1web-app.org · webapp16 Mar 2007
- CVE-2007-341826İzleyin
The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction
OrtaCVSS 6,5İstismar yokEPSS %1web-app.org · webapp26 Haz 2007
- CVE-2007-182725İzleyin
Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corru
OrtaCVSS 6,0İstismar yokEPSS %2web-app.org · webapp2 Nis 2007
- CVE-2007-118225İzleyin
WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.
OrtaCVSS 6,4İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-183124İzleyin
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.
OrtaCVSS 6,0İstismar yokEPSS %1web-app.org · webapp2 Nis 2007
- CVE-2007-117723İzleyin
WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum P
OrtaCVSS 5,8İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2004-174222İzleyin
Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %7web-app.org · webapp24 Ağu 2004
- CVE-2007-118722İzleyin
WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive
OrtaCVSS 5,5İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-183220İzleyin
web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using perc
OrtaCVSS 5,0İstismar yokEPSS %1web-app.org · webapp2 Nis 2007
- CVE-2007-118120İzleyin
WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack ve
OrtaCVSS 5,0İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-118620İzleyin
WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
OrtaCVSS 5,0İstismar yokEPSS %1web-app.org · webapp2 Mar 2007
- CVE-2007-118520İzleyin
The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown i
OrtaCVSS 5,0İstismar yokEPSS %1web-app.org · webapp2 Mar 2007