ens kayıtları
ens üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2018-19510İstismar yok | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.ens · webgalamb · CWE-89 | Kritik9,8 | — | %20,0 | 21 Mar 2019 |
40Planlayın | CVE-2018-19514İstismar yok | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.ens · webgalamb · CWE-434 | Kritik9,8 | — | %4,9 | 21 Mar 2019 |
40Planlayın | CVE-2018-19515İstismar yok | In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.ens · webgalamb · CWE-863 | Kritik9,8 | — | %2,9 | 21 Mar 2019 |
31İzleyin | CVE-2018-19513İstismar yok | In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenens · webgalamb · CWE-532 | Yüksek7,5 | — | %2,1 | 21 Mar 2019 |
30İzleyin | CVE-2018-19512İstismar yok | In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by auens · webgalamb · CWE-22 | Yüksek7,2 | — | %7,2 | 21 Mar 2019 |
26İzleyin | CVE-2018-19511İstismar yok | wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator pens · webgalamb · CWE-352 | Orta6,5 | — | %0,7 | 21 Mar 2019 |
24İzleyin | CVE-2018-19509İstismar yok | wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodinens · webgalamb · CWE-79 | Orta6,1 | — | %1,1 | 21 Mar 2019 |
- CVE-2018-1951045Planlayın
subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.
KritikCVSS 9,8İstismar yokEPSS %20ens · webgalamb21 Mar 2019
- CVE-2018-1951440Planlayın
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.
KritikCVSS 9,8İstismar yokEPSS %5ens · webgalamb21 Mar 2019
- CVE-2018-1951540Planlayın
In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.
KritikCVSS 9,8İstismar yokEPSS %3ens · webgalamb21 Mar 2019
- CVE-2018-1951331İzleyin
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filen
YüksekCVSS 7,5İstismar yokEPSS %2ens · webgalamb21 Mar 2019
- CVE-2018-1951230İzleyin
In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by au
YüksekCVSS 7,2İstismar yokEPSS %7ens · webgalamb21 Mar 2019
- CVE-2018-1951126İzleyin
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator p
OrtaCVSS 6,5İstismar yokEPSS %1ens · webgalamb21 Mar 2019
- CVE-2018-1950924İzleyin
wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodin
OrtaCVSS 6,1İstismar yokEPSS %1ens · webgalamb21 Mar 2019