İçeriğe atla
Noroxi

ez kayıtları

ez üreticisine ait 23 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%13
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

23 kayıt
  • CVE-2007-4493
    41Planlayın

    eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has un

    KritikCVSS 10,0İstismar yokEPSS %2

    ez · ez publish22 Ağu 2007

  • CVE-2020-10806
    40Planlayın

    eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.

    KritikCVSS 9,8İstismar yokEPSS %2

    ez · ez publish-kernel22 Mar 2020

  • CVE-2005-4853
    37İzleyin

    The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 2005081

    KritikCVSS 9,4İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2008-6844
    31İzleyin

    The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    ez · ez publish2 Tem 2009

  • CVE-2012-1565
    31İzleyin

    Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure dire

    YüksekCVSS 7,5İstismar yokEPSS %2

    ez · ez publish6 Eki 2012

  • CVE-2010-2672
    30İzleyin

    Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1

    YüksekCVSS 7,5İstismar yokEPSS %1

    ez · ez publish8 Tem 2010

  • CVE-2003-0310
    28İzleyin

    Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

    OrtaCVSS 6,8Kavram kanıtıEPSS %3

    ez · ez publish16 Haz 2003

  • CVE-2012-4053
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the aut

    OrtaCVSS 6,8İstismar yokEPSS %1

    ez · ez publish25 Tem 2012

  • CVE-2019-12139
    24İzleyin

    An XSS issue was discovered in the Admin UI in eZ Platform 2.x.

    OrtaCVSS 6,1İstismar yokEPSS %1

    ez · ezplatform-admin-ui16 May 2019

  • eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk

    OrtaCVSS 6,1İstismar yokEPSS %1

    ez · ez publish2 Oca 2018

  • CVE-2007-4494
    21İzleyin

    The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote atta

    OrtaCVSS 5,0İstismar yokEPSS %2

    ez · ez publish22 Ağu 2007

  • CVE-2005-4852
    20İzleyin

    The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to

    OrtaCVSS 5,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2005-4854
    20İzleyin

    eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authentic

    OrtaCVSS 5,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2005-4856
    20İzleyin

    The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle aut

    OrtaCVSS 5,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2005-4850
    20İzleyin

    eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers

    OrtaCVSS 5,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2006-0938
    17İzleyin

    Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via

    OrtaCVSS 4,3İstismar yokEPSS %1

    ez · ez publish28 Şub 2006

  • CVE-2010-2671
    17İzleyin

    Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary

    OrtaCVSS 4,3İstismar yokEPSS %1

    ez · ez publish8 Tem 2010

  • CVE-2006-7219
    16İzleyin

    eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to

    OrtaCVSS 4,0İstismar yokEPSS %1

    ez · ez publish6 Tem 2007

  • CVE-2006-7218
    16İzleyin

    eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allow

    OrtaCVSS 4,0İstismar yokEPSS %1

    ez · ez publish6 Tem 2007

  • CVE-2005-4857
    16İzleyin

    eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial

    OrtaCVSS 4,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2005-4851
    16İzleyin

    eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypas

    OrtaCVSS 4,0İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2005-4855
    14İzleyin

    Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does n

    DüşükCVSS 3,5İstismar yokEPSS %1

    ez · ez publish31 Ara 2005

  • CVE-2012-1597
    11İzleyin

    Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 a

    DüşükCVSS 2,6Kavram kanıtıEPSS %4

    ez · ezjscore16 Ağu 2012