playsms kayıtları
playsms üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %7,1
- Silahlaştırılmış
- 3 · %21,4
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 637 gün
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-697 Incorrect Comparison1
- CWE-384 Session Fixation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2020-8644Silahlaştırılmış | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.playsms · playsms · CWE-94 | Kritik9,8 | KEV | %86,7 | 5 Şub 2020 |
62Bu hafta | CVE-2017-9101Silahlaştırılmış | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header aplaysms · playsms · CWE-434 | Kritik9,8 | — | %76,7 | 21 May 2017 |
54Planlayın | CVE-2017-9080Silahlaştırılmış | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.playsms · playsms · CWE-434 | Yüksek8,8 | — | %62,3 | 19 May 2017 |
40Planlayın | CVE-2021-40373Kavram kanıtı | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executplaysms · playsms · CWE-94 | Kritik9,8 | — | %4,7 | 10 Eyl 2021 |
39İzleyin | CVE-2022-47034İstismar yok | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Kritik9,8 | — | %0,8 | 13 Şub 2023 |
33İzleyin | CVE-2009-0103Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1playsms · playsms · CWE-94 | Yüksek7,5 | — | %10,1 | 9 Oca 2009 |
32İzleyin | CVE-2008-5881Kavram kanıtı | Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directplaysms · playsms · CWE-22 | Yüksek7,5 | — | %7,3 | 9 Oca 2009 |
30İzleyin | CVE-2004-2263Kavram kanıtı | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statementsplaysms · playsms | Yüksek7,5 | — | %1,4 | 31 Ara 2004 |
26İzleyin | CVE-2020-15018İstismar yok | playSMS through 1.4.3 is vulnerable to session fixation.playsms · playsms · CWE-384 | Orta6,5 | — | %0,9 | 24 Haz 2020 |
25İzleyin | CVE-2024-8880İstismar yok | playSMS Template index.php code injectionplaysms · playsms · CWE-94 | Orta6,3 | — | %0,7 | 15 Eyl 2024 |
20İzleyin | CVE-2024-6469İstismar yok | playSMS Template injectionplaysms · playsms · CWE-74 | Orta5,1 | — | %0,7 | 3 Tem 2024 |
20İzleyin | CVE-2024-6470İstismar yok | playSMS Template injectionplaysms · playsms · CWE-74 | Orta5,1 | — | %0,4 | 3 Tem 2024 |
20İzleyin | CVE-2024-6251İstismar yok | playSMS New Phonebook cross site scriptingplaysms · playsms · CWE-80 | Orta5,1 | — | %0,4 | 22 Haz 2024 |
18İzleyin | CVE-2005-4432Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the playsms · playsms | Orta4,3 | — | %2,0 | 20 Ara 2005 |
- CVE-2020-864495Hemen
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87playsms · playsms5 Şub 2020
- CVE-2017-910162Bu hafta
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a
KritikCVSS 9,8SilahlaştırılmışEPSS %77playsms · playsms21 May 2017
- CVE-2017-908054Planlayın
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.
YüksekCVSS 8,8SilahlaştırılmışEPSS %62playsms · playsms19 May 2017
- CVE-2021-4037340Planlayın
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut
KritikCVSS 9,8Kavram kanıtıEPSS %5playsms · playsms10 Eyl 2021
- CVE-2022-4703439İzleyin
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
KritikCVSS 9,8İstismar yokEPSS %1playsms · playsms13 Şub 2023
- CVE-2009-010333İzleyin
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1
YüksekCVSS 7,5Kavram kanıtıEPSS %10playsms · playsms9 Oca 2009
- CVE-2008-588132İzleyin
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct
YüksekCVSS 7,5Kavram kanıtıEPSS %7playsms · playsms9 Oca 2009
- CVE-2004-226330İzleyin
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements
YüksekCVSS 7,5Kavram kanıtıEPSS %1playsms · playsms31 Ara 2004
- CVE-2020-1501826İzleyin
playSMS through 1.4.3 is vulnerable to session fixation.
OrtaCVSS 6,5İstismar yokEPSS %1playsms · playsms24 Haz 2020
- CVE-2024-888025İzleyin
playSMS Template index.php code injection
OrtaCVSS 6,3İstismar yokEPSS %1playsms · playsms15 Eyl 2024
- CVE-2024-646920İzleyin
playSMS Template injection
OrtaCVSS 5,1İstismar yokEPSS %1playsms · playsms3 Tem 2024
- CVE-2024-647020İzleyin
playSMS Template injection
OrtaCVSS 5,1İstismar yokEPSS %0playsms · playsms3 Tem 2024
- CVE-2024-625120İzleyin
playSMS New Phonebook cross site scripting
OrtaCVSS 5,1İstismar yokEPSS %0playsms · playsms22 Haz 2024
- CVE-2005-443218İzleyin
Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 4,3Kavram kanıtıEPSS %2playsms · playsms20 Ara 2005