Записи orpak
6 опубликованных записей вендора orpak.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-310 Cryptographic Issues1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2017-14728Эксплойта нет | An authentication bypass was found in an unknown area of the SiteOmat source code.orpak · siteomat · CWE-798 | Критическая9,8 | — | 6,3 % | 3 июн. 2019 г. |
40В плане | CVE-2017-14851Эксплойта нет | A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25.orpak · siteomat · CWE-89 | Критическая9,8 | — | 4,1 % | 3 июн. 2019 г. |
38Наблюдать | CVE-2017-14854Эксплойта нет | A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution.orpak · siteomat · CWE-119 | Критическая9,1 | — | 7,3 % | 3 июн. 2019 г. |
35Наблюдать | CVE-2017-14853Эксплойта нет | The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a dorpak · siteomat · CWE-94 | Высокая8,6 | — | 3,8 % | 3 июн. 2019 г. |
34Наблюдать | CVE-2017-14852Эксплойта нет | An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL corpak · siteomat · CWE-310 | Высокая8,6 | — | 1,0 % | 3 июн. 2019 г. |
25Наблюдать | CVE-2017-14850Эксплойта нет | All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to imorpak · siteomat · CWE-79 | Средняя6,1 | — | 1,7 % | 3 июн. 2019 г. |
- CVE-2017-1472841В плане
An authentication bypass was found in an unknown area of the SiteOmat source code.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %orpak · siteomat3 июн. 2019 г.
- CVE-2017-1485140В плане
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %orpak · siteomat3 июн. 2019 г.
- CVE-2017-1485438Наблюдать
A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution.
КритическаяCVSS 9,1Эксплойта нетEPSS 7 %orpak · siteomat3 июн. 2019 г.
- CVE-2017-1485335Наблюдать
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a d
ВысокаяCVSS 8,6Эксплойта нетEPSS 4 %orpak · siteomat3 июн. 2019 г.
- CVE-2017-1485234Наблюдать
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL c
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %orpak · siteomat3 июн. 2019 г.
- CVE-2017-1485025Наблюдать
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to im
СредняяCVSS 6,1Эксплойта нетEPSS 2 %orpak · siteomat3 июн. 2019 г.