Записи machform
15 опубликованных записей вендора machform.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2018-6411Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-434 | Критическая9,8 | — | 5,8 % | 26 мая 2018 г. |
40В плане | CVE-2018-6410Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-89 | Критическая9,8 | — | 4,9 % | 26 мая 2018 г. |
39Наблюдать | CVE-2024-37762Proof of concept | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.machform · machform · CWE-434 | Критическая9,9 | — | 1,5 % | 1 июл. 2024 г. |
35Наблюдать | CVE-2024-37765Proof of concept | Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.machform · machform · CWE-89 | Высокая8,8 | — | 0,8 % | 1 июл. 2024 г. |
35Наблюдать | CVE-2021-20102Эксплойта нет | Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.machform · machform · CWE-352 | Высокая8,8 | — | 0,5 % | 29 июн. 2021 г. |
33Наблюдать | CVE-2021-20104Эксплойта нет | Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uplmachform · machform · CWE-434 | Высокая8,1 | — | 2,2 % | 29 июн. 2021 г. |
31Наблюдать | CVE-2013-4948Proof of concept | SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.machform · machform · CWE-89 | Высокая7,5 | — | 3,5 % | 29 июл. 2013 г. |
29Наблюдать | CVE-2013-4949Proof of concept | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fimachform · machform | Средняя6,8 | — | 5,5 % | 29 июл. 2013 г. |
25Наблюдать | CVE-2018-6409Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-22 | Средняя5,3 | — | 14,6 % | 26 мая 2018 г. |
24Наблюдать | CVE-2021-20105Эксплойта нет | Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.machform · machform · CWE-601 | Средняя6,1 | — | 0,7 % | 29 июн. 2021 г. |
24Наблюдать | CVE-2021-20101Эксплойта нет | Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.machform · machform · CWE-74 | Средняя6,1 | — | 0,7 % | 29 июн. 2021 г. |
24Наблюдать | CVE-2021-20103Эксплойта нет | Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded withmachform · machform · CWE-79 | Средняя6,1 | — | 0,7 % | 29 июн. 2021 г. |
21Наблюдать | CVE-2024-37763Proof of concept | MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can viemachform · machform · CWE-79 | Средняя5,4 | — | 0,7 % | 1 июл. 2024 г. |
21Наблюдать | CVE-2024-37764Proof of concept | MachForm up to version 19 is affected by an authenticated stored cross-site scripting.machform · machform · CWE-79 | Средняя5,4 | — | 0,6 % | 1 июл. 2024 г. |
18Наблюдать | CVE-2013-4950Proof of concept | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the elmachform · machform · CWE-79 | Средняя4,3 | — | 3,9 % | 29 июл. 2013 г. |
- CVE-2018-641141В плане
An issue was discovered in Appnitro MachForm before 4.2.3.
КритическаяCVSS 9,8Proof of conceptEPSS 6 %machform · machform26 мая 2018 г.
- CVE-2018-641040В плане
An issue was discovered in Appnitro MachForm before 4.2.3.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %machform · machform26 мая 2018 г.
- CVE-2024-3776239Наблюдать
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
КритическаяCVSS 9,9Proof of conceptEPSS 1 %machform · machform1 июл. 2024 г.
- CVE-2024-3776535Наблюдать
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %machform · machform1 июл. 2024 г.
- CVE-2021-2010235Наблюдать
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %machform · machform29 июн. 2021 г.
- CVE-2021-2010433Наблюдать
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments upl
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %machform · machform29 июн. 2021 г.
- CVE-2013-494831Наблюдать
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %machform · machform29 июл. 2013 г.
- CVE-2013-494929Наблюдать
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fi
СредняяCVSS 6,8Proof of conceptEPSS 5 %machform · machform29 июл. 2013 г.
- CVE-2018-640925Наблюдать
An issue was discovered in Appnitro MachForm before 4.2.3.
СредняяCVSS 5,3Proof of conceptEPSS 15 %machform · machform26 мая 2018 г.
- CVE-2021-2010524Наблюдать
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %machform · machform29 июн. 2021 г.
- CVE-2021-2010124Наблюдать
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %machform · machform29 июн. 2021 г.
- CVE-2021-2010324Наблюдать
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with
СредняяCVSS 6,1Эксплойта нетEPSS 1 %machform · machform29 июн. 2021 г.
- CVE-2024-3776321Наблюдать
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can vie
СредняяCVSS 5,4Proof of conceptEPSS 1 %machform · machform1 июл. 2024 г.
- CVE-2024-3776421Наблюдать
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
СредняяCVSS 5,4Proof of conceptEPSS 1 %machform · machform1 июл. 2024 г.
- CVE-2013-495018Наблюдать
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the el
СредняяCVSS 4,3Proof of conceptEPSS 4 %machform · machform29 июл. 2013 г.