İçeriğe atla
Noroxi

5none kayıtları

5none üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %8,3
Silahlaştırılmış
1 · %8,3
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
1058 gün

Tüm kayıtlar

12 kayıt
  • An issue was discovered in NoneCms V1.3.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    5none · nonecms11 Ara 2018

  • CVE-2018-7219
    35İzleyin

    application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p

    YüksekCVSS 8,8İstismar yokEPSS %1

    5none · nonecms19 Şub 2018

  • CVE-2020-18646
    30İzleyin

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

    YüksekCVSS 7,5İstismar yokEPSS %2

    5none · nonecms22 Haz 2021

  • CVE-2020-18647
    30İzleyin

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

    YüksekCVSS 7,5İstismar yokEPSS %2

    5none · nonecms22 Haz 2021

  • CVE-2018-6029
    30İzleyin

    The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and

    YüksekCVSS 7,5İstismar yokEPSS %1

    5none · nonecms23 Oca 2018

  • CVE-2018-6022
    26İzleyin

    Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del

    OrtaCVSS 6,5İstismar yokEPSS %1

    5none · nonecms23 Oca 2018

  • CVE-2019-16721
    26İzleyin

    NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.

    OrtaCVSS 6,5İstismar yokEPSS %1

    5none · nonecms23 Eyl 2019

  • CVE-2020-23371
    24İzleyin

    Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo

    OrtaCVSS 6,1İstismar yokEPSS %1

    5none · nonecms10 May 2021

  • CVE-2020-18282
    24İzleyin

    Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur

    OrtaCVSS 6,1İstismar yokEPSS %1

    5none · nonecms8 May 2023

  • CVE-2020-23376
    24İzleyin

    NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj

    OrtaCVSS 6,1İstismar yokEPSS %0

    5none · nonecms10 May 2021

  • CVE-2020-23373
    21İzleyin

    Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w

    OrtaCVSS 5,4İstismar yokEPSS %1

    5none · nonecms10 May 2021

  • CVE-2020-23374
    21İzleyin

    Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra

    OrtaCVSS 5,4İstismar yokEPSS %1

    5none · nonecms10 May 2021