Webeoc

Vendor:

First CVE: Jul 18, 2005 · Active for 21 years

7
Total CVEs
More Total CVEs than 85% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webeoc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 18, 2005
21 years ago
Most Recent CVE
Dec 5, 2005
7,540 days ago

CVE Severity & Scoring

Webeoc7 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
Jul 18, 200510.025NONO
Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.
Jul 18, 20057.519NONO
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out va
Dec 5, 20055.015NONO
WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Username
Jul 18, 20055.015NONO
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
Dec 5, 20054.014NONO
Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.
Jul 18, 20054.314NONO
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource cons
Jul 18, 20052.111NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Webeoc

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.214.31.0%00