Записи docebo
13 опубликованных записей вендора docebo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-31362Эксплойта нет | Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability.docebo · docebo · CWE-434 | Высокая8,8 | — | 18,3 % | 23 июн. 2022 г. |
39Наблюдать | CVE-2022-31361Эксплойта нет | Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.docebo · docebo · CWE-89 | Критическая9,8 | — | 1,4 % | 23 июн. 2022 г. |
31Наблюдать | CVE-2008-7153Proof of concept | SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote atdocebo · docebo · CWE-89 | Высокая7,5 | — | 2,4 % | 2 сент. 2009 г. |
31Наблюдать | CVE-2006-6963Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in thedocebo · docebo | Высокая7,5 | — | 1,8 % | 29 янв. 2007 г. |
30Наблюдать | CVE-2009-4742Proof of concept | Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameterdocebo · docebo · CWE-89 | Высокая7,5 | — | 0,6 % | 26 мар. 2010 г. |
27Наблюдать | CVE-2006-6957Эксплойта нет | PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows rdocebo · docebo · CWE-94 | Средняя6,8 | — | 1,4 % | 29 янв. 2007 г. |
24Наблюдать | CVE-2011-5135Proof of concept | Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and eardocebo · docebolms · CWE-89 | Средняя6,0 | — | 0,9 % | 30 авг. 2012 г. |
23Наблюдать | CVE-2006-2576Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Средняя5,1 | — | 9,1 % | 24 мая 2006 г. |
21Наблюдать | CVE-2008-7154Proof of concept | Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) docebo · docebo · CWE-200 | Средняя5,0 | — | 2,5 % | 2 сент. 2009 г. |
21Наблюдать | CVE-2006-2577Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Средняя5,1 | — | 2,4 % | 24 мая 2006 г. |
21Наблюдать | CVE-2006-3107Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Средняя5,1 | — | 1,7 % | 20 июн. 2006 г. |
20Наблюдать | CVE-2011-3726Эксплойта нет | DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation docebo · docebolms · CWE-200 | Средняя5,0 | — | 1,3 % | 23 сент. 2011 г. |
18Наблюдать | CVE-2007-1240Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script docebo · docebo · CWE-79 | Средняя4,3 | — | 3,2 % | 3 мар. 2007 г. |
- CVE-2022-3136240В плане
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %docebo · docebo23 июн. 2022 г.
- CVE-2022-3136139Наблюдать
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %docebo · docebo23 июн. 2022 г.
- CVE-2008-715331Наблюдать
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote at
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %docebo · docebo2 сент. 2009 г.
- CVE-2006-696331Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %docebo · docebo29 янв. 2007 г.
- CVE-2009-474230Наблюдать
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %docebo · docebo26 мар. 2010 г.
- CVE-2006-695727Наблюдать
PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows r
СредняяCVSS 6,8Эксплойта нетEPSS 1 %docebo · docebo29 янв. 2007 г.
- CVE-2011-513524Наблюдать
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and ear
СредняяCVSS 6,0Proof of conceptEPSS 1 %docebo · docebolms30 авг. 2012 г.
- CVE-2006-257623Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
СредняяCVSS 5,1Proof of conceptEPSS 9 %docebo · docebo24 мая 2006 г.
- CVE-2008-715421Наблюдать
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2)
СредняяCVSS 5,0Proof of conceptEPSS 3 %docebo · docebo2 сент. 2009 г.
- CVE-2006-257721Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
СредняяCVSS 5,1Proof of conceptEPSS 2 %docebo · docebo24 мая 2006 г.
- CVE-2006-310721Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
СредняяCVSS 5,1Эксплойта нетEPSS 2 %docebo · docebo20 июн. 2006 г.
- CVE-2011-372620Наблюдать
DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
СредняяCVSS 5,0Эксплойта нетEPSS 1 %docebo · docebolms23 сент. 2011 г.
- CVE-2007-124018Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 3 %docebo · docebo3 мар. 2007 г.