eprints kayıtları
eprints üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-611 Improper Restriction of XML External Entity Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-3342İstismar yok | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latexeprints · eprints · CWE-78 | Kritik9,8 | — | %4,2 | 1 Mar 2021 |
40Planlayın | CVE-2021-26703İstismar yok | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase eprints · eprints · CWE-611 | Kritik9,8 | — | %4,0 | 1 Mar 2021 |
40Planlayın | CVE-2021-26476İstismar yok | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.eprints · eprints · CWE-78 | Kritik9,8 | — | %3,1 | 1 Mar 2021 |
36İzleyin | CVE-2021-26704İstismar yok | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.eprints · eprints · CWE-78 | Yüksek8,8 | — | %3,1 | 1 Mar 2021 |
26İzleyin | CVE-2021-26475Kavram kanıtı | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.eprints · eprints · CWE-79 | Orta6,1 | — | %7,3 | 1 Mar 2021 |
25İzleyin | CVE-2021-26702Kavram kanıtı | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.eprints · eprints · CWE-79 | Orta6,1 | — | %3,1 | 1 Mar 2021 |
- CVE-2021-334240Planlayın
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex
KritikCVSS 9,8İstismar yokEPSS %4eprints · eprints1 Mar 2021
- CVE-2021-2670340Planlayın
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase
KritikCVSS 9,8İstismar yokEPSS %4eprints · eprints1 Mar 2021
- CVE-2021-2647640Planlayın
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
KritikCVSS 9,8İstismar yokEPSS %3eprints · eprints1 Mar 2021
- CVE-2021-2670436İzleyin
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
YüksekCVSS 8,8İstismar yokEPSS %3eprints · eprints1 Mar 2021
- CVE-2021-2647526İzleyin
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
OrtaCVSS 6,1Kavram kanıtıEPSS %7eprints · eprints1 Mar 2021
- CVE-2021-2670225İzleyin
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
OrtaCVSS 6,1Kavram kanıtıEPSS %3eprints · eprints1 Mar 2021