İçeriğe atla
Noroxi

Mfscripts kayıtları

mfscripts üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2019-20062
    39İzleyin

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u

    KritikCVSS 9,8İstismar yokEPSS %2

    mfscripts · yetishare10 Şub 2020

  • CVE-2019-19735
    36İzleyin

    class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro

    KritikCVSS 9,1İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19734
    35İzleyin

    _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.

    YüksekCVSS 8,8İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-20059
    35İzleyin

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    mfscripts · yetishare10 Şub 2020

  • CVE-2019-19737
    35İzleyin

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ

    YüksekCVSS 8,8İstismar yokEPSS %0

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-20060
    30İzleyin

    MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.

    YüksekCVSS 7,5İstismar yokEPSS %1

    mfscripts · yetishare10 Şub 2020

  • CVE-2019-20061
    30İzleyin

    The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea

    YüksekCVSS 7,5İstismar yokEPSS %1

    mfscripts · yetishare10 Şub 2020

  • CVE-2019-19739
    30İzleyin

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann

    YüksekCVSS 7,5İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19732
    28İzleyin

    translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS

    YüksekCVSS 7,2İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19738
    24İzleyin

    log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,

    OrtaCVSS 6,1İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19733
    24İzleyin

    _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or

    OrtaCVSS 6,1İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19736
    24İzleyin

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c

    OrtaCVSS 6,1İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19805
    21İzleyin

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether

    OrtaCVSS 5,3İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2019-19806
    21İzleyin

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi

    OrtaCVSS 5,3İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019