dbhcms project kayıtları
dbhcms project üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-19889İstismar yok | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.dbhcms project · dbhcms · CWE-352 | Yüksek8,8 | — | %0,5 | 24 Ağu 2020 |
32İzleyin | CVE-2020-19886İstismar yok | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.dbhcms project · dbhcms · CWE-352 | Yüksek8,1 | — | %0,4 | 24 Ağu 2020 |
30İzleyin | CVE-2020-19878İstismar yok | DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A dbhcms project · dbhcms | Yüksek7,5 | — | %1,5 | 24 Ağu 2020 |
28İzleyin | CVE-2020-19891İstismar yok | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_codbhcms project · dbhcms · CWE-787 | Yüksek7,2 | — | %1,4 | 24 Ağu 2020 |
24İzleyin | CVE-2020-19880İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticadbhcms project · dbhcms · CWE-79 | Orta6,1 | — | %0,9 | 24 Ağu 2020 |
24İzleyin | CVE-2020-19879İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,dbhcms project · dbhcms · CWE-79 | Orta6,1 | — | %0,7 | 24 Ağu 2020 |
23İzleyin | CVE-2020-19888İstismar yok | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache odbhcms project · dbhcms · CWE-287 | Orta5,9 | — | %0,7 | 24 Ağu 2020 |
22İzleyin | CVE-2020-19877İstismar yok | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/.dbhcms project · dbhcms · CWE-22 | Orta5,3 | — | %1,7 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19890İstismar yok | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter funcdbhcms project · dbhcms · CWE-639 | Orta4,9 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19885İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcdbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19881İstismar yok | DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_namdbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19887İstismar yok | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable dbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19883İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remotdbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19882İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menudbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,9 | 24 Ağu 2020 |
19İzleyin | CVE-2020-19884İstismar yok | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.dbhcms project · dbhcms · CWE-79 | Orta4,8 | — | %0,7 | 24 Ağu 2020 |
- CVE-2020-1988935İzleyin
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
YüksekCVSS 8,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988632İzleyin
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
YüksekCVSS 8,1İstismar yokEPSS %0dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1987830İzleyin
DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A
YüksekCVSS 7,5İstismar yokEPSS %2dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1989128İzleyin
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_co
YüksekCVSS 7,2İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988024İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthentica
OrtaCVSS 6,1İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1987924İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,
OrtaCVSS 6,1İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988823İzleyin
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache o
OrtaCVSS 5,9İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1987722İzleyin
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/.
OrtaCVSS 5,3İstismar yokEPSS %2dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1989019İzleyin
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter func
OrtaCVSS 4,9İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988519İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhc
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988119İzleyin
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_nam
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988719İzleyin
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988319İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remot
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988219İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menu
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020
- CVE-2020-1988419İzleyin
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
OrtaCVSS 4,8İstismar yokEPSS %1dbhcms project · dbhcms24 Ağu 2020