Jaws
Jaws · 11 CVEs
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme…
Dec 23, 2020
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?re…
Dec 23, 2020
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files…
Feb 18, 2009
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL command…
Jun 28, 2006
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2,…
Dec 1, 2005
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .…
Aug 20, 2005
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web scrip…
Aug 20, 2005
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie s…
Aug 20, 2005
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute a…
Jul 10, 2005
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attac…
May 10, 2005
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attacke…
Apr 24, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-35657 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing… | HIGH | 2.51% | Dec 23, 2020 |
| CVE-2020-35656 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadg… | HIGH | 2.51% | Dec 23, 2020 |
| CVE-2009-0645 | Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language,… | MEDIUM | 6.28% | Feb 18, 2009 |
| CVE-2006-3292 | SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in… | HIGH | 4.67% | Jun 28, 2006 |
| CVE-2005-3955 | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remot… | MEDIUM | 5.58% | Dec 1, 2005 |
| CVE-2004-2445 | Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter. | MEDIUM | 8.43% | Aug 20, 2005 |
| CVE-2004-2444 | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | MEDIUM | 4.20% | Aug 20, 2005 |
| CVE-2004-2443 | Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, w… | HIGH | 8.85% | Aug 20, 2005 |
| CVE-2005-2179 | PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter. | MEDIUM | 2.06% | Jul 10, 2005 |
| CVE-2004-2067 | SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass… | HIGH | 2.79% | May 10, 2005 |
| CVE-2005-1231 | Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTM… | MEDIUM | 1.94% | Apr 24, 2005 |
Showing 1 to 11 of 11 CVEs