efrontlearning kayıtları
efrontlearning üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2010-1918Kavram kanıtı | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chefrontlearning · efront · CWE-89 | Yüksek7,5 | — | %1,2 | 12 May 2010 |
29İzleyin | CVE-2010-1003Kavram kanıtı | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to includeefrontlearning · efront · CWE-22 | Orta6,8 | — | %5,0 | 19 Mar 2010 |
28İzleyin | CVE-2008-7026Kavram kanıtı | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arefrontlearning · efront · CWE-264 | Orta6,8 | — | %4,7 | 21 Ağu 2009 |
28İzleyin | CVE-2009-3660Kavram kanıtı | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remoefrontlearning · efront · CWE-94 | Orta6,8 | — | %1,9 | 11 Eki 2009 |
26İzleyin | CVE-2015-4461İstismar yok | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via aefrontlearning · efront · CWE-22 | Orta6,5 | — | %1,2 | 5 Şub 2018 |
26İzleyin | CVE-2015-4463İstismar yok | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by apefrontlearning · efront · CWE-434 | Orta6,5 | — | %1,2 | 25 Tem 2017 |
26İzleyin | CVE-2015-4462İstismar yok | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read efrontlearning · efront · CWE-434 | Orta6,5 | — | %1,1 | 25 Tem 2017 |
25İzleyin | CVE-2012-4269İstismar yok | Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file withefrontlearning · efront | Orta6,0 | — | %2,1 | 13 Ağu 2012 |
20İzleyin | CVE-2012-6515İstismar yok | eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in tefrontlearning · efront · CWE-200 | Orta5,0 | — | %1,5 | 23 Oca 2013 |
18İzleyin | CVE-2014-4033Kavram kanıtı | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to efrontlearning · efront · CWE-79 | Orta4,3 | — | %3,3 | 11 Haz 2014 |
17İzleyin | CVE-2012-1048Kavram kanıtı | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly otherefrontlearning · efront community \+\+ · CWE-79 | Orta4,3 | — | %1,5 | 12 Şub 2012 |
15İzleyin | CVE-2013-7194Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated adminefrontlearning · efront · CWE-79 | Düşük3,5 | — | %2,6 | 20 Ara 2013 |
14İzleyin | CVE-2012-4270İstismar yok | Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the sefrontlearning · efront · CWE-79 | Düşük3,5 | — | %1,0 | 13 Ağu 2012 |
- CVE-2010-191830İzleyin
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ch
YüksekCVSS 7,5Kavram kanıtıEPSS %1efrontlearning · efront12 May 2010
- CVE-2010-100329İzleyin
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include
OrtaCVSS 6,8Kavram kanıtıEPSS %5efrontlearning · efront19 Mar 2010
- CVE-2008-702628İzleyin
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute ar
OrtaCVSS 6,8Kavram kanıtıEPSS %5efrontlearning · efront21 Ağu 2009
- CVE-2009-366028İzleyin
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remo
OrtaCVSS 6,8Kavram kanıtıEPSS %2efrontlearning · efront11 Eki 2009
- CVE-2015-446126İzleyin
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a
OrtaCVSS 6,5İstismar yokEPSS %1efrontlearning · efront5 Şub 2018
- CVE-2015-446326İzleyin
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by ap
OrtaCVSS 6,5İstismar yokEPSS %1efrontlearning · efront25 Tem 2017
- CVE-2015-446226İzleyin
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read
OrtaCVSS 6,5İstismar yokEPSS %1efrontlearning · efront25 Tem 2017
- CVE-2012-426925İzleyin
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with
OrtaCVSS 6,0İstismar yokEPSS %2efrontlearning · efront13 Ağu 2012
- CVE-2012-651520İzleyin
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in t
OrtaCVSS 5,0İstismar yokEPSS %1efrontlearning · efront23 Oca 2013
- CVE-2014-403318İzleyin
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to
OrtaCVSS 4,3Kavram kanıtıEPSS %3efrontlearning · efront11 Haz 2014
- CVE-2012-104817İzleyin
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other
OrtaCVSS 4,3Kavram kanıtıEPSS %1efrontlearning · efront community \+\+12 Şub 2012
- CVE-2013-719415İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated admin
DüşükCVSS 3,5Kavram kanıtıEPSS %3efrontlearning · efront20 Ara 2013
- CVE-2012-427014İzleyin
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the s
DüşükCVSS 3,5İstismar yokEPSS %1efrontlearning · efront13 Ağu 2012