quickbox kayıtları
quickbox üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-269 Improper Privilege Management1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-13448Kavram kanıtı | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the serverquickbox · quickbox · CWE-78 | Yüksek8,8 | — | %17,4 | 1 Haz 2020 |
36İzleyin | CVE-2021-44981İstismar yok | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); quickbox · quickbox · CWE-78 | Yüksek8,8 | — | %3,7 | 24 Oca 2022 |
36İzleyin | CVE-2020-13694İstismar yok | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a passwordquickbox · quickbox · CWE-78 | Yüksek8,8 | — | %2,0 | 1 Haz 2020 |
29İzleyin | CVE-2020-13695İstismar yok | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as roquickbox · quickbox · CWE-269 | Yüksek7,2 | — | %1,7 | 1 Haz 2020 |
24İzleyin | CVE-2021-45281İstismar yok | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input foquickbox · quickbox · CWE-79 | Orta6,1 | — | %0,7 | 7 Şub 2022 |
- CVE-2020-1344840Planlayın
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server
YüksekCVSS 8,8Kavram kanıtıEPSS %17quickbox · quickbox1 Haz 2020
- CVE-2021-4498136İzleyin
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec('');
YüksekCVSS 8,8İstismar yokEPSS %4quickbox · quickbox24 Oca 2022
- CVE-2020-1369436İzleyin
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password
YüksekCVSS 8,8İstismar yokEPSS %2quickbox · quickbox1 Haz 2020
- CVE-2020-1369529İzleyin
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as ro
YüksekCVSS 7,2İstismar yokEPSS %2quickbox · quickbox1 Haz 2020
- CVE-2021-4528124İzleyin
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input fo
OrtaCVSS 6,1İstismar yokEPSS %1quickbox · quickbox7 Şub 2022