webwizguide kayıtları
webwizguide üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2007-1548Kavram kanıtı | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certawebwizguide · web wiz forums · CWE-89 | Yüksek7,5 | — | %1,8 | 20 Mar 2007 |
23İzleyin | CVE-2008-3392İstismar yok | Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_webwizguide · web wiz forum · CWE-352 | Orta5,8 | — | %0,6 | 31 Tem 2008 |
21İzleyin | CVE-2003-1571Kavram kanıtı | Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dowwebwizguide · web wiz guestbook · CWE-264 | Orta5,0 | — | %2,6 | 2 Nis 2009 |
17İzleyin | CVE-2008-3391Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via twebwizguide · web wiz forum · CWE-79 | Orta4,3 | — | %1,5 | 31 Tem 2008 |
17İzleyin | CVE-2008-3367İstismar yok | Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attacwebwizguide · web wiz rich text editor · CWE-79 | Orta4,3 | — | %1,3 | 30 Tem 2008 |
- CVE-2007-154831İzleyin
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certa
YüksekCVSS 7,5Kavram kanıtıEPSS %2webwizguide · web wiz forums20 Mar 2007
- CVE-2008-339223İzleyin
Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_
OrtaCVSS 5,8İstismar yokEPSS %1webwizguide · web wiz forum31 Tem 2008
- CVE-2003-157121İzleyin
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow
OrtaCVSS 5,0Kavram kanıtıEPSS %3webwizguide · web wiz guestbook2 Nis 2009
- CVE-2008-339117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 4,3Kavram kanıtıEPSS %2webwizguide · web wiz forum31 Tem 2008
- CVE-2008-336717İzleyin
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attac
OrtaCVSS 4,3İstismar yokEPSS %1webwizguide · web wiz rich text editor30 Tem 2008