İçeriğe atla
Noroxi

eprints kayıtları

eprints üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

6 kayıt
  • CVE-2021-3342
    40Planlayın

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex

    KritikCVSS 9,8İstismar yokEPSS %4

    eprints · eprints1 Mar 2021

  • CVE-2021-26703
    40Planlayın

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase

    KritikCVSS 9,8İstismar yokEPSS %4

    eprints · eprints1 Mar 2021

  • CVE-2021-26476
    40Planlayın

    EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

    KritikCVSS 9,8İstismar yokEPSS %3

    eprints · eprints1 Mar 2021

  • CVE-2021-26704
    36İzleyin

    EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

    YüksekCVSS 8,8İstismar yokEPSS %3

    eprints · eprints1 Mar 2021

  • CVE-2021-26475
    26İzleyin

    EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

    OrtaCVSS 6,1Kavram kanıtıEPSS %7

    eprints · eprints1 Mar 2021

  • CVE-2021-26702
    25İzleyin

    EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    eprints · eprints1 Mar 2021