razorcms kayıtları
razorcms üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2018-17986İstismar yok | rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.razorcms · razorcms · CWE-352 | Yüksek8,8 | — | %0,6 | 4 Eki 2018 |
30İzleyin | CVE-2009-1463İstismar yok | Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving contrazorcms · razorcms · CWE-94 | Yüksek7,5 | — | %1,6 | 28 Nis 2009 |
28İzleyin | CVE-2012-1900Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the autherazorcms · razorcms · CWE-352 | Orta6,8 | — | %2,6 | 22 Eki 2012 |
28İzleyin | CVE-2009-1462İstismar yok | The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsirazorcms · razorcms · CWE-264 | Yüksek7,2 | — | %0,4 | 28 Nis 2009 |
27İzleyin | CVE-2012-6038Kavram kanıtı | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which arazorcms · razorcms · CWE-22 | Orta6,5 | — | %2,7 | 26 Kas 2012 |
27İzleyin | CVE-2009-1459İstismar yok | Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administratorrazorcms · razorcms · CWE-352 | Orta6,8 | — | %0,7 | 28 Nis 2009 |
21İzleyin | CVE-2018-19905İstismar yok | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.razorcms · razorcms · CWE-79 | Orta5,4 | — | %0,7 | 31 Ara 2018 |
21İzleyin | CVE-2018-19906İstismar yok | Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.razorcms · razorcms · CWE-79 | Orta5,4 | — | %0,7 | 31 Ara 2018 |
21İzleyin | CVE-2018-16727İstismar yok | razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.razorcms · razorcms · CWE-79 | Orta5,4 | — | %0,6 | 12 Eyl 2018 |
21İzleyin | CVE-2018-16726İstismar yok | razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.razorcms · razorcms · CWE-79 | Orta5,4 | — | %0,6 | 12 Eyl 2018 |
18İzleyin | CVE-2009-1458Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary webrazorcms · razorcms · CWE-79 | Orta4,3 | — | %1,8 | 28 Nis 2009 |
18İzleyin | CVE-2009-1460İstismar yok | razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's passworazorcms · razorcms · CWE-264 | Orta4,6 | — | %0,4 | 28 Nis 2009 |
17İzleyin | CVE-2010-5051Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary webrazorcms · razorcms · CWE-79 | Orta4,3 | — | %1,5 | 22 Kas 2011 |
16İzleyin | CVE-2012-5918Kavram kanıtı | razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.razorcms · razorcms · CWE-264 | Orta4,0 | — | %1,5 | 19 Kas 2012 |
14İzleyin | CVE-2009-1461İstismar yok | Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inrazorcms · razorcms · CWE-79 | Düşük3,5 | — | %0,9 | 28 Nis 2009 |
- CVE-2018-1798635İzleyin
rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.
YüksekCVSS 8,8İstismar yokEPSS %1razorcms · razorcms4 Eki 2018
- CVE-2009-146330İzleyin
Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving cont
YüksekCVSS 7,5İstismar yokEPSS %2razorcms · razorcms28 Nis 2009
- CVE-2012-190028İzleyin
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authe
OrtaCVSS 6,8Kavram kanıtıEPSS %3razorcms · razorcms22 Eki 2012
- CVE-2009-146228İzleyin
The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsi
YüksekCVSS 7,2İstismar yokEPSS %0razorcms · razorcms28 Nis 2009
- CVE-2012-603827İzleyin
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which a
OrtaCVSS 6,5Kavram kanıtıEPSS %3razorcms · razorcms26 Kas 2012
- CVE-2009-145927İzleyin
Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrator
OrtaCVSS 6,8İstismar yokEPSS %1razorcms · razorcms28 Nis 2009
- CVE-2018-1990521İzleyin
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
OrtaCVSS 5,4İstismar yokEPSS %1razorcms · razorcms31 Ara 2018
- CVE-2018-1990621İzleyin
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
OrtaCVSS 5,4İstismar yokEPSS %1razorcms · razorcms31 Ara 2018
- CVE-2018-1672721İzleyin
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
OrtaCVSS 5,4İstismar yokEPSS %1razorcms · razorcms12 Eyl 2018
- CVE-2018-1672621İzleyin
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
OrtaCVSS 5,4İstismar yokEPSS %1razorcms · razorcms12 Eyl 2018
- CVE-2009-145818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2razorcms · razorcms28 Nis 2009
- CVE-2009-146018İzleyin
razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's passwo
OrtaCVSS 4,6İstismar yokEPSS %0razorcms · razorcms28 Nis 2009
- CVE-2010-505117İzleyin
Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2razorcms · razorcms22 Kas 2011
- CVE-2012-591816İzleyin
razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.
OrtaCVSS 4,0Kavram kanıtıEPSS %2razorcms · razorcms19 Kas 2012
- CVE-2009-146114İzleyin
Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to in
DüşükCVSS 3,5İstismar yokEPSS %1razorcms · razorcms28 Nis 2009