intercom kayıtları
intercom üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-295 Improper Certificate Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-10817İstismar yok | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.intercom · malion · CWE-287 | Kritik9,8 | — | %3,1 | 4 Ağu 2017 |
40Planlayın | CVE-2017-10816İstismar yok | SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Rintercom · malion · CWE-89 | Kritik9,8 | — | %2,2 | 4 Ağu 2017 |
40Planlayın | CVE-2017-10818İstismar yok | MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection seintercom · malion · CWE-798 | Kritik9,8 | — | %1,8 | 4 Ağu 2017 |
33İzleyin | CVE-2017-10815İstismar yok | MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"intercom · malion · CWE-287 | Yüksek8,1 | — | %2,3 | 4 Ağu 2017 |
31İzleyin | CVE-2019-14365İstismar yok | The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.intercom · intercom · CWE-200 | Yüksek7,5 | — | %1,9 | 12 Kas 2019 |
27İzleyin | CVE-2014-3881İstismar yok | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authenticintercom · web kyukincho · CWE-352 | Orta6,8 | — | %0,6 | 27 Haz 2014 |
23İzleyin | CVE-2017-10819İstismar yok | MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatiointercom · malion · CWE-295 | Orta5,9 | — | %0,8 | 4 Ağu 2017 |
17İzleyin | CVE-2014-2006İstismar yok | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web scriptintercom · web kyukincho · CWE-79 | Orta4,3 | — | %1,1 | 27 Haz 2014 |
- CVE-2017-1081740Planlayın
MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.
KritikCVSS 9,8İstismar yokEPSS %3intercom · malion4 Ağu 2017
- CVE-2017-1081640Planlayın
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via R
KritikCVSS 9,8İstismar yokEPSS %2intercom · malion4 Ağu 2017
- CVE-2017-1081840Planlayın
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection se
KritikCVSS 9,8İstismar yokEPSS %2intercom · malion4 Ağu 2017
- CVE-2017-1081533İzleyin
MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"
YüksekCVSS 8,1İstismar yokEPSS %2intercom · malion4 Ağu 2017
- CVE-2019-1436531İzleyin
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.
YüksekCVSS 7,5İstismar yokEPSS %2intercom · intercom12 Kas 2019
- CVE-2014-388127İzleyin
Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentic
OrtaCVSS 6,8İstismar yokEPSS %1intercom · web kyukincho27 Haz 2014
- CVE-2017-1081923İzleyin
MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatio
OrtaCVSS 5,9İstismar yokEPSS %1intercom · malion4 Ağu 2017
- CVE-2014-200617İzleyin
Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1intercom · web kyukincho27 Haz 2014