roundup-tracker kayıtları
roundup-tracker üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
26İzleyin | CVE-2008-1475İstismar yok | The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restroundup-tracker · roundup · CWE-264 | Orta6,4 | — | %1,8 | 24 Mar 2008 |
24İzleyin | CVE-2019-10904İstismar yok | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.debian · debian linux · CWE-79 | Orta6,1 | — | %1,6 | 6 Nis 2019 |
24İzleyin | CVE-2012-6133İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML vroundup-tracker · roundup · CWE-79 | Orta6,1 | — | %1,6 | 30 Oca 2020 |
23İzleyin | CVE-2004-1444Kavram kanıtı | Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via ..roundup-tracker · roundup · CWE-22 | Orta5,0 | — | %8,9 | 31 Ara 2004 |
21İzleyin | CVE-2024-39126İstismar yok | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.roundup-tracker · roundup · CWE-79 | Orta5,4 | — | %0,3 | 17 Tem 2024 |
21İzleyin | CVE-2024-39124İstismar yok | In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.roundup-tracker · roundup · CWE-79 | Orta5,4 | — | %0,3 | 17 Tem 2024 |
21İzleyin | CVE-2024-39125İstismar yok | Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.roundup-tracker · roundup · CWE-79 | Orta5,4 | — | %0,3 | 17 Tem 2024 |
18İzleyin | CVE-2010-2491İstismar yok | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script orroundup-tracker · roundup · CWE-79 | Orta4,3 | — | %2,6 | 24 Eyl 2010 |
18İzleyin | CVE-2012-6131İstismar yok | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script orroundup-tracker · roundup · CWE-79 | Orta4,3 | — | %2,0 | 11 Nis 2014 |
18İzleyin | CVE-2012-6130İstismar yok | Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web scrroundup-tracker · roundup · CWE-79 | Orta4,3 | — | %2,0 | 11 Nis 2014 |
18İzleyin | CVE-2012-6132İstismar yok | Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otkroundup-tracker · roundup · CWE-79 | Orta4,3 | — | %1,8 | 10 Nis 2014 |
17İzleyin | CVE-2014-6276İstismar yok | schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authentiroundup-tracker · roundup · CWE-264 | Orta4,3 | — | %1,5 | 13 Nis 2016 |
17İzleyin | CVE-2008-1474İstismar yok | Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-sroundup-tracker · roundup · CWE-79 | Orta4,3 | — | %1,5 | 24 Mar 2008 |
- CVE-2008-147526İzleyin
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read rest
OrtaCVSS 6,4İstismar yokEPSS %2roundup-tracker · roundup24 Mar 2008
- CVE-2019-1090424İzleyin
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
OrtaCVSS 6,1İstismar yokEPSS %2debian · debian linux6 Nis 2019
- CVE-2012-613324İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 6,1İstismar yokEPSS %2roundup-tracker · roundup30 Oca 2020
- CVE-2004-144423İzleyin
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via ..
OrtaCVSS 5,0Kavram kanıtıEPSS %9roundup-tracker · roundup31 Ara 2004
- CVE-2024-3912621İzleyin
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
OrtaCVSS 5,4İstismar yokEPSS %0roundup-tracker · roundup17 Tem 2024
- CVE-2024-3912421İzleyin
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
OrtaCVSS 5,4İstismar yokEPSS %0roundup-tracker · roundup17 Tem 2024
- CVE-2024-3912521İzleyin
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
OrtaCVSS 5,4İstismar yokEPSS %0roundup-tracker · roundup17 Tem 2024
- CVE-2010-249118İzleyin
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %3roundup-tracker · roundup24 Eyl 2010
- CVE-2012-613118İzleyin
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %2roundup-tracker · roundup11 Nis 2014
- CVE-2012-613018İzleyin
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web scr
OrtaCVSS 4,3İstismar yokEPSS %2roundup-tracker · roundup11 Nis 2014
- CVE-2012-613218İzleyin
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk
OrtaCVSS 4,3İstismar yokEPSS %2roundup-tracker · roundup10 Nis 2014
- CVE-2014-627617İzleyin
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenti
OrtaCVSS 4,3İstismar yokEPSS %2roundup-tracker · roundup13 Nis 2016
- CVE-2008-147417İzleyin
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-s
OrtaCVSS 4,3İstismar yokEPSS %1roundup-tracker · roundup24 Mar 2008