webspell kayıtları
webspell üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-1160İstismar yok | webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability webspell · webspell · CWE-287 | Kritik10,0 | — | %2,7 | 2 Mar 2007 |
30İzleyin | CVE-2007-4028İstismar yok | Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files webspell · webspell | Yüksek7,5 | — | %1,5 | 26 Tem 2007 |
30İzleyin | CVE-2010-4861Kavram kanıtı | SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search paramewebspell · webspell · CWE-89 | Yüksek7,5 | — | %1,2 | 5 Eki 2011 |
30İzleyin | CVE-2006-0728Kavram kanıtı | SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the twebspell · webspell | Yüksek7,5 | — | %1,2 | 16 Şub 2006 |
30İzleyin | CVE-2007-0502Kavram kanıtı | SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID paramwebspell · webspell | Yüksek7,5 | — | %1,1 | 25 Oca 2007 |
30İzleyin | CVE-2006-5388Kavram kanıtı | SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the gwebspell · webspell | Yüksek7,5 | — | %1,1 | 18 Eki 2006 |
30İzleyin | CVE-2007-1163Kavram kanıtı | SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via twebspell · webspell · CWE-89 | Yüksek7,5 | — | %1,1 | 2 Mar 2007 |
30İzleyin | CVE-2007-0492İstismar yok | Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commanwebspell · webspell | Yüksek7,5 | — | %1,1 | 24 Oca 2007 |
28İzleyin | CVE-2009-1912Kavram kanıtı | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbwebspell · webspell · CWE-22 | Orta6,8 | — | %3,2 | 4 Haz 2009 |
27İzleyin | CVE-2007-1019Kavram kanıtı | SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary webspell · webspell | Orta6,8 | — | %1,2 | 21 Şub 2007 |
27İzleyin | CVE-2007-1154İstismar yok | SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerabwebspell · webspell · CWE-89 | Orta6,8 | — | %1,0 | 2 Mar 2007 |
23İzleyin | CVE-2007-2369Kavram kanıtı | Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to php · php | Orta5,0 | — | %8,4 | 30 Nis 2007 |
22İzleyin | CVE-2006-4782Kavram kanıtı | src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain swebspell · webspell | Orta5,4 | — | %3,2 | 14 Eyl 2006 |
21İzleyin | CVE-2007-2368Kavram kanıtı | picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.webspell · webspell | Orta5,0 | — | %2,3 | 30 Nis 2007 |
20İzleyin | CVE-2006-4783İstismar yok | SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execwebspell · webspell | Orta5,1 | — | %1,2 | 14 Eyl 2006 |
18İzleyin | CVE-2007-6309Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or webspell · webspell · CWE-79 | Orta4,3 | — | %4,2 | 11 Ara 2007 |
18İzleyin | CVE-2009-1408Kavram kanıtı | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attwebspell · webspell · CWE-79 | Orta4,3 | — | %2,0 | 24 Nis 2009 |
18İzleyin | CVE-2007-1155İstismar yok | Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via twebspell · webspell · CWE-20 | Orta4,6 | — | %1,0 | 2 Mar 2007 |
17İzleyin | CVE-2008-0574Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML viawebspell · webspell · CWE-79 | Orta4,3 | — | %1,5 | 4 Şub 2008 |
17İzleyin | CVE-2008-1481Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via twebspell · webspell · CWE-79 | Orta4,3 | — | %1,4 | 24 Mar 2008 |
17İzleyin | CVE-2008-0575İstismar yok | Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmiwebspell · webspell · CWE-352 | Orta4,3 | — | %0,5 | 4 Şub 2008 |
- CVE-2007-116041Planlayın
webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability
KritikCVSS 10,0İstismar yokEPSS %3webspell · webspell2 Mar 2007
- CVE-2007-402830İzleyin
Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files
YüksekCVSS 7,5İstismar yokEPSS %2webspell · webspell26 Tem 2007
- CVE-2010-486130İzleyin
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parame
YüksekCVSS 7,5Kavram kanıtıEPSS %1webspell · webspell5 Eki 2011
- CVE-2006-072830İzleyin
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the t
YüksekCVSS 7,5Kavram kanıtıEPSS %1webspell · webspell16 Şub 2006
- CVE-2007-050230İzleyin
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID param
YüksekCVSS 7,5Kavram kanıtıEPSS %1webspell · webspell25 Oca 2007
- CVE-2006-538830İzleyin
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the g
YüksekCVSS 7,5Kavram kanıtıEPSS %1webspell · webspell18 Eki 2006
- CVE-2007-116330İzleyin
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via t
YüksekCVSS 7,5Kavram kanıtıEPSS %1webspell · webspell2 Mar 2007
- CVE-2007-049230İzleyin
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5İstismar yokEPSS %1webspell · webspell24 Oca 2007
- CVE-2009-191228İzleyin
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arb
OrtaCVSS 6,8Kavram kanıtıEPSS %3webspell · webspell4 Haz 2009
- CVE-2007-101927İzleyin
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary
OrtaCVSS 6,8Kavram kanıtıEPSS %1webspell · webspell21 Şub 2007
- CVE-2007-115427İzleyin
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerab
OrtaCVSS 6,8İstismar yokEPSS %1webspell · webspell2 Mar 2007
- CVE-2007-236923İzleyin
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to
OrtaCVSS 5,0Kavram kanıtıEPSS %8php · php30 Nis 2007
- CVE-2006-478222İzleyin
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain s
OrtaCVSS 5,4Kavram kanıtıEPSS %3webspell · webspell14 Eyl 2006
- CVE-2007-236821İzleyin
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
OrtaCVSS 5,0Kavram kanıtıEPSS %2webspell · webspell30 Nis 2007
- CVE-2006-478320İzleyin
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to exec
OrtaCVSS 5,1İstismar yokEPSS %1webspell · webspell14 Eyl 2006
- CVE-2007-630918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %4webspell · webspell11 Ara 2007
- CVE-2009-140818İzleyin
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote att
OrtaCVSS 4,3Kavram kanıtıEPSS %2webspell · webspell24 Nis 2009
- CVE-2007-115518İzleyin
Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via t
OrtaCVSS 4,6İstismar yokEPSS %1webspell · webspell2 Mar 2007
- CVE-2008-057417İzleyin
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3Kavram kanıtıEPSS %2webspell · webspell4 Şub 2008
- CVE-2008-148117İzleyin
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 4,3Kavram kanıtıEPSS %1webspell · webspell24 Mar 2008
- CVE-2008-057517İzleyin
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmi
OrtaCVSS 4,3İstismar yokEPSS %1webspell · webspell4 Şub 2008