HelpDezk kayıtları
helpdezk üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-285 Improper Authorization1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-8337İstismar yok | Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackhelpdezk · helpdezk · CWE-434 | Kritik9,8 | — | %4,8 | 3 Oca 2020 |
39İzleyin | CVE-2017-14145İstismar yok | HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, relahelpdezk · helpdezk · CWE-89 | Kritik9,8 | — | %1,2 | 5 Eyl 2017 |
36İzleyin | CVE-2017-7447Kavram kanıtı | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.helpdezk · helpdezk · CWE-352 | Yüksek8,8 | — | %3,5 | 5 Nis 2017 |
36İzleyin | CVE-2017-7446Kavram kanıtı | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.helpdezk · helpdezk · CWE-352 | Yüksek8,8 | — | %3,1 | 5 Nis 2017 |
35İzleyin | CVE-2017-14146İstismar yok | HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk · helpdezk · CWE-94 | Yüksek8,8 | — | %1,3 | 5 Eyl 2017 |
34İzleyin | CVE-2023-3037İstismar yok | HelpDezk Community improper authorizationhelpdezk · helpdezk · CWE-285 | Yüksek8,6 | — | %0,6 | 4 Eki 2023 |
30İzleyin | CVE-2023-3038İstismar yok | HelpDezk Community improper authorizationhelpdezk · helpdezk · CWE-89 | Yüksek7,5 | — | %0,6 | 4 Eki 2023 |
- CVE-2014-833740Planlayın
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attack
KritikCVSS 9,8İstismar yokEPSS %5helpdezk · helpdezk3 Oca 2020
- CVE-2017-1414539İzleyin
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, rela
KritikCVSS 9,8İstismar yokEPSS %1helpdezk · helpdezk5 Eyl 2017
- CVE-2017-744736İzleyin
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
YüksekCVSS 8,8Kavram kanıtıEPSS %3helpdezk · helpdezk5 Nis 2017
- CVE-2017-744636İzleyin
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
YüksekCVSS 8,8Kavram kanıtıEPSS %3helpdezk · helpdezk5 Nis 2017
- CVE-2017-1414635İzleyin
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the
YüksekCVSS 8,8İstismar yokEPSS %1helpdezk · helpdezk5 Eyl 2017
- CVE-2023-303734İzleyin
HelpDezk Community improper authorization
YüksekCVSS 8,6İstismar yokEPSS %1helpdezk · helpdezk4 Eki 2023
- CVE-2023-303830İzleyin
HelpDezk Community improper authorization
YüksekCVSS 7,5İstismar yokEPSS %1helpdezk · helpdezk4 Eki 2023