Записи positive software
12 опубликованных записей вендора positive software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-2633Эксплойта нет | Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files positive software · sitestudio | Критическая10,0 | — | 2,4 % | 13 мая 2007 г. |
40В плане | CVE-2008-1049Эксплойта нет | Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and positive software · h-sphere | Критическая10,0 | — | 1,5 % | 27 февр. 2008 г. |
33Наблюдать | CVE-2003-1247Proof of concept | Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::positive software · h-sphere | Высокая7,5 | — | 10,0 % | 31 дек. 2003 г. |
32Наблюдать | CVE-2005-4261Эксплойта нет | Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectpositive software · cp\+ | Высокая7,8 | — | 1,7 % | 15 дек. 2005 г. |
31Наблюдать | CVE-2003-1248Эксплойта нет | H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parametpositive software · h-sphere | Высокая7,5 | — | 2,2 % | 31 дек. 2003 г. |
27Наблюдать | CVE-2005-1605Эксплойта нет | Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML positive software · sitestudio | Средняя6,8 | — | 1,5 % | 16 мая 2005 г. |
27Наблюдать | CVE-2008-4448Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perfpositive software · h-sphere · CWE-352 | Средняя6,8 | — | 0,7 % | 6 окт. 2008 г. |
27Наблюдать | CVE-2006-6382Эксплойта нет | The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which apositive software · h-sphere | Средняя6,8 | — | 0,3 % | 7 дек. 2006 г. |
18Наблюдать | CVE-2005-1606Proof of concept | H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, whipositive software · h-sphere winbox | Средняя4,6 | — | 0,8 % | 16 мая 2005 г. |
17Наблюдать | CVE-2008-4447Proof of concept | Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbipositive software · h-sphere · CWE-79 | Средняя4,3 | — | 1,4 % | 6 окт. 2008 г. |
17Наблюдать | CVE-2006-0193Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earpositive software · h-sphere | Средняя4,3 | — | 1,3 % | 13 янв. 2006 г. |
10Наблюдать | CVE-2006-3278Эксплойта нет | Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTMLpositive software · h-sphere | Низкая2,6 | — | 1,3 % | 28 июн. 2006 г. |
- CVE-2007-263341В плане
Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %positive software · sitestudio13 мая 2007 г.
- CVE-2008-104940В плане
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %positive software · h-sphere27 февр. 2008 г.
- CVE-2003-124733Наблюдать
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %positive software · h-sphere31 дек. 2003 г.
- CVE-2005-426132Наблюдать
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vect
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %positive software · cp\+15 дек. 2005 г.
- CVE-2003-124831Наблюдать
H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile paramet
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %positive software · h-sphere31 дек. 2003 г.
- CVE-2005-160527Наблюдать
Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,8Эксплойта нетEPSS 2 %positive software · sitestudio16 мая 2005 г.
- CVE-2008-444827Наблюдать
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perf
СредняяCVSS 6,8Эксплойта нетEPSS 1 %positive software · h-sphere6 окт. 2008 г.
- CVE-2006-638227Наблюдать
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which a
СредняяCVSS 6,8Эксплойта нетEPSS 0 %positive software · h-sphere7 дек. 2006 г.
- CVE-2005-160618Наблюдать
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, whi
СредняяCVSS 4,6Proof of conceptEPSS 1 %positive software · h-sphere winbox16 мая 2005 г.
- CVE-2008-444717Наблюдать
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbi
СредняяCVSS 4,3Proof of conceptEPSS 1 %positive software · h-sphere6 окт. 2008 г.
- CVE-2006-019317Наблюдать
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and ear
СредняяCVSS 4,3Эксплойта нетEPSS 1 %positive software · h-sphere13 янв. 2006 г.
- CVE-2006-327810Наблюдать
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML
НизкаяCVSS 2,6Эксплойта нетEPSS 1 %positive software · h-sphere28 июн. 2006 г.