phome kayıtları
phome üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-693 Protection Mechanism Failure1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-18869İstismar yok | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/ephome · empirecms · CWE-22 | Kritik9,8 | — | %3,7 | 31 Eki 2018 |
40Planlayın | CVE-2020-22937İstismar yok | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious cphome · empirecms · CWE-94 | Kritik9,8 | — | %2,8 | 17 Ağu 2021 |
39İzleyin | CVE-2018-20300İstismar yok | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this phome · empirecms · CWE-94 | Kritik9,8 | — | %1,6 | 19 Ara 2018 |
39İzleyin | CVE-2022-28585İstismar yok | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.phpphome · empirecms · CWE-89 | Kritik9,8 | — | %1,0 | 3 May 2022 |
35İzleyin | CVE-2018-18086İstismar yok | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.phome · empirecms · CWE-434 | Yüksek8,8 | — | %1,5 | 9 Eki 2018 |
35İzleyin | CVE-2018-18449İstismar yok | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16phome · empirecms · CWE-352 | Yüksek8,8 | — | %0,7 | 7 Mar 2019 |
35İzleyin | CVE-2018-16339İstismar yok | An issue was discovered in EmpireCMS 7.0.phome · empirecms · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Eyl 2018 |
29İzleyin | CVE-2018-19462İstismar yok | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filenamphome · empirecms · CWE-89 | Yüksek7,2 | — | %2,2 | 7 Haz 2019 |
28İzleyin | CVE-2012-5777İstismar yok | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assiphome · empirecms · CWE-94 | Orta6,8 | — | %2,2 | 15 Kas 2012 |
28İzleyin | CVE-2023-50162İstismar yok | SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the Dophome · empirecms · CWE-89 | Yüksek7,2 | — | %1,0 | 8 Oca 2024 |
24İzleyin | CVE-2019-12362İstismar yok | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.phome · empirecms · CWE-79 | Orta6,1 | — | %0,8 | 27 May 2019 |
24İzleyin | CVE-2019-12361İstismar yok | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page temphome · empirecms · CWE-79 | Orta6,1 | — | %0,4 | 27 May 2019 |
22İzleyin | CVE-2018-6881İstismar yok | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.dedecms · dedecms · CWE-200 | Orta5,3 | — | %2,2 | 11 Şub 2018 |
22İzleyin | CVE-2018-6880İstismar yok | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.phome · empirecms · CWE-668 | Orta5,3 | — | %1,8 | 11 Şub 2018 |
22İzleyin | CVE-2025-15422İstismar yok | EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanismphome · empirecms · CWE-693 | Orta5,5 | — | %1,3 | 1 Oca 2026 |
19İzleyin | CVE-2018-19461İstismar yok | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.phome · empirecms · CWE-79 | Orta4,8 | — | %0,9 | 7 Haz 2019 |
8İzleyin | CVE-2025-15423İstismar yok | EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted uploadphome · empirecms · CWE-284 | Düşük2,1 | — | %0,4 | 1 Oca 2026 |
- CVE-2018-1886940Planlayın
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e
KritikCVSS 9,8İstismar yokEPSS %4phome · empirecms31 Eki 2018
- CVE-2020-2293740Planlayın
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious c
KritikCVSS 9,8İstismar yokEPSS %3phome · empirecms17 Ağu 2021
- CVE-2018-2030039İzleyin
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this
KritikCVSS 9,8İstismar yokEPSS %2phome · empirecms19 Ara 2018
- CVE-2022-2858539İzleyin
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
KritikCVSS 9,8İstismar yokEPSS %1phome · empirecms3 May 2022
- CVE-2018-1808635İzleyin
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
YüksekCVSS 8,8İstismar yokEPSS %1phome · empirecms9 Eki 2018
- CVE-2018-1844935İzleyin
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16
YüksekCVSS 8,8İstismar yokEPSS %1phome · empirecms7 Mar 2019
- CVE-2018-1633935İzleyin
An issue was discovered in EmpireCMS 7.0.
YüksekCVSS 8,8İstismar yokEPSS %1phome · empirecms2 Eyl 2018
- CVE-2018-1946229İzleyin
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filenam
YüksekCVSS 7,2İstismar yokEPSS %2phome · empirecms7 Haz 2019
- CVE-2012-577728İzleyin
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assi
OrtaCVSS 6,8İstismar yokEPSS %2phome · empirecms15 Kas 2012
- CVE-2023-5016228İzleyin
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the Do
YüksekCVSS 7,2İstismar yokEPSS %1phome · empirecms8 Oca 2024
- CVE-2019-1236224İzleyin
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
OrtaCVSS 6,1İstismar yokEPSS %1phome · empirecms27 May 2019
- CVE-2019-1236124İzleyin
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page tem
OrtaCVSS 6,1İstismar yokEPSS %0phome · empirecms27 May 2019
- CVE-2018-688122İzleyin
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
OrtaCVSS 5,3İstismar yokEPSS %2dedecms · dedecms11 Şub 2018
- CVE-2018-688022İzleyin
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
OrtaCVSS 5,3İstismar yokEPSS %2phome · empirecms11 Şub 2018
- CVE-2025-1542222İzleyin
EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism
OrtaCVSS 5,5İstismar yokEPSS %1phome · empirecms1 Oca 2026
- CVE-2018-1946119İzleyin
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
OrtaCVSS 4,8İstismar yokEPSS %1phome · empirecms7 Haz 2019
- CVE-2025-154238İzleyin
EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
DüşükCVSS 2,1İstismar yokEPSS %0phome · empirecms1 Oca 2026