Mfscripts kayıtları
mfscripts üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-20062İstismar yok | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until umfscripts · yetishare · CWE-287 | Kritik9,8 | — | %1,6 | 10 Şub 2020 |
36İzleyin | CVE-2019-19735İstismar yok | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micromfscripts · yetishare · CWE-916 | Kritik9,1 | — | %0,8 | 30 Ara 2019 |
35İzleyin | CVE-2019-19734İstismar yok | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.mfscripts · yetishare · CWE-89 | Yüksek8,8 | — | %1,1 | 30 Ara 2019 |
35İzleyin | CVE-2019-20059Kavram kanıtı | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 mfscripts · yetishare · CWE-89 | Yüksek8,8 | — | %0,9 | 10 Şub 2020 |
35İzleyin | CVE-2019-19737İstismar yok | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requmfscripts · yetishare · CWE-352 | Yüksek8,8 | — | %0,5 | 30 Ara 2019 |
30İzleyin | CVE-2019-20060İstismar yok | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.mfscripts · yetishare · CWE-922 | Yüksek7,5 | — | %1,4 | 10 Şub 2020 |
30İzleyin | CVE-2019-20061İstismar yok | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleamfscripts · yetishare · CWE-319 | Yüksek7,5 | — | %0,9 | 10 Şub 2020 |
30İzleyin | CVE-2019-19739İstismar yok | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channmfscripts · yetishare · CWE-311 | Yüksek7,5 | — | %0,7 | 30 Ara 2019 |
28İzleyin | CVE-2019-19732İstismar yok | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSmfscripts · yetishare · CWE-89 | Yüksek7,2 | — | %1,1 | 30 Ara 2019 |
24İzleyin | CVE-2019-19738İstismar yok | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, mfscripts · yetishare · CWE-79 | Orta6,1 | — | %0,7 | 30 Ara 2019 |
24İzleyin | CVE-2019-19733İstismar yok | _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize ormfscripts · yetishare · CWE-79 | Orta6,1 | — | %0,7 | 30 Ara 2019 |
24İzleyin | CVE-2019-19736İstismar yok | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which cmfscripts · yetishare · CWE-732 | Orta6,1 | — | %0,6 | 30 Ara 2019 |
21İzleyin | CVE-2019-19805İstismar yok | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whethermfscripts · yetishare · CWE-203 | Orta5,3 | — | %1,0 | 30 Ara 2019 |
21İzleyin | CVE-2019-19806İstismar yok | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confimfscripts · yetishare · CWE-209 | Orta5,3 | — | %1,0 | 30 Ara 2019 |
- CVE-2019-2006239İzleyin
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u
KritikCVSS 9,8İstismar yokEPSS %2mfscripts · yetishare10 Şub 2020
- CVE-2019-1973536İzleyin
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro
KritikCVSS 9,1İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1973435İzleyin
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.
YüksekCVSS 8,8İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-2005935İzleyin
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0
YüksekCVSS 8,8Kavram kanıtıEPSS %1mfscripts · yetishare10 Şub 2020
- CVE-2019-1973735İzleyin
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ
YüksekCVSS 8,8İstismar yokEPSS %0mfscripts · yetishare30 Ara 2019
- CVE-2019-2006030İzleyin
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.
YüksekCVSS 7,5İstismar yokEPSS %1mfscripts · yetishare10 Şub 2020
- CVE-2019-2006130İzleyin
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea
YüksekCVSS 7,5İstismar yokEPSS %1mfscripts · yetishare10 Şub 2020
- CVE-2019-1973930İzleyin
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann
YüksekCVSS 7,5İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1973228İzleyin
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS
YüksekCVSS 7,2İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1973824İzleyin
log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,
OrtaCVSS 6,1İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1973324İzleyin
_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or
OrtaCVSS 6,1İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1973624İzleyin
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c
OrtaCVSS 6,1İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1980521İzleyin
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether
OrtaCVSS 5,3İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2019-1980621İzleyin
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi
OrtaCVSS 5,3İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019