ehcp kayıtları
ehcp üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-287 Improper Authentication1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-522 Insufficiently Protected Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2018-6458İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lackehcp · easy hosting control panel · CWE-352 | Yüksek8,8 | — | %10,0 | 11 May 2018 |
36İzleyin | CVE-2018-6361İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.ehcp · easy hosting control panel · CWE-79 | Orta6,1 | — | %38,4 | 11 May 2018 |
31İzleyin | CVE-2018-6618İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.ehcp · easy hosting control panel · CWE-522 | Yüksek7,8 | — | %0,5 | 11 May 2018 |
31İzleyin | CVE-2018-6617İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database usehcp · easy hosting control panel · CWE-287 | Yüksek7,8 | — | %0,4 | 11 May 2018 |
31İzleyin | CVE-2018-6619İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing aehcp · easy hosting control panel · CWE-327 | Yüksek7,8 | — | %0,4 | 11 May 2018 |
26İzleyin | CVE-2025-50926İstismar yok | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Emaiehcp · easy hosting control panel · CWE-89 | Orta6,5 | — | %0,3 | 19 Ağu 2025 |
25İzleyin | CVE-2025-50927İstismar yok | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to ehcp · easy hosting control panel · CWE-79 | Orta6,3 | — | %0,2 | 8 Ağu 2025 |
24İzleyin | CVE-2018-6362İstismar yok | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.ehcp · easy hosting control panel · CWE-79 | Orta6,1 | — | %1,0 | 11 May 2018 |
24İzleyin | CVE-2025-50859İstismar yok | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackersehcp · easy hosting control panel · CWE-79 | Orta6,1 | — | %0,3 | 22 Ağu 2025 |
24İzleyin | CVE-2025-50858İstismar yok | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attaehcp · easy hosting control panel · CWE-79 | Orta6,1 | — | %0,2 | 22 Ağu 2025 |
21İzleyin | CVE-2025-50860İstismar yok | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulehcp · easy hosting control panel · CWE-89 | Orta5,4 | — | %0,2 | 21 Ağu 2025 |
19İzleyin | CVE-2025-50928İstismar yok | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settinehcp · easy hosting control panel · CWE-89 | Orta4,8 | — | %0,2 | 8 Ağu 2025 |
- CVE-2018-645838İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack
YüksekCVSS 8,8İstismar yokEPSS %10ehcp · easy hosting control panel11 May 2018
- CVE-2018-636136İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
OrtaCVSS 6,1İstismar yokEPSS %38ehcp · easy hosting control panel11 May 2018
- CVE-2018-661831İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
YüksekCVSS 7,8İstismar yokEPSS %0ehcp · easy hosting control panel11 May 2018
- CVE-2018-661731İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database us
YüksekCVSS 7,8İstismar yokEPSS %0ehcp · easy hosting control panel11 May 2018
- CVE-2018-661931İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing a
YüksekCVSS 7,8İstismar yokEPSS %0ehcp · easy hosting control panel11 May 2018
- CVE-2025-5092626İzleyin
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Emai
OrtaCVSS 6,5İstismar yokEPSS %0ehcp · easy hosting control panel19 Ağu 2025
- CVE-2025-5092725İzleyin
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to
OrtaCVSS 6,3İstismar yokEPSS %0ehcp · easy hosting control panel8 Ağu 2025
- CVE-2018-636224İzleyin
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
OrtaCVSS 6,1İstismar yokEPSS %1ehcp · easy hosting control panel11 May 2018
- CVE-2025-5085924İzleyin
Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers
OrtaCVSS 6,1İstismar yokEPSS %0ehcp · easy hosting control panel22 Ağu 2025
- CVE-2025-5085824İzleyin
Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated atta
OrtaCVSS 6,1İstismar yokEPSS %0ehcp · easy hosting control panel22 Ağu 2025
- CVE-2025-5086021İzleyin
SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipul
OrtaCVSS 5,4İstismar yokEPSS %0ehcp · easy hosting control panel21 Ağu 2025
- CVE-2025-5092819İzleyin
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settin
OrtaCVSS 4,8İstismar yokEPSS %0ehcp · easy hosting control panel8 Ağu 2025