İçeriğe atla
Noroxi

s9y kayıtları

s9y üreticisine ait 61 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
12
Düzeltme kaydı olan
%6,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

61 kayıt
  • CVE-2011-1134
    40Planlayın

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code

    KritikCVSS 9,8İstismar yokEPSS %3

    s9y · serendipity5 Kas 2019

  • CVE-2016-10082
    40Planlayın

    include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during

    KritikCVSS 9,8İstismar yokEPSS %3

    s9y · serendipity30 Ara 2016

  • CVE-2020-10964
    40Planlayın

    Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a

    KritikCVSS 9,8İstismar yokEPSS %3

    s9y · serendipity25 Mar 2020

  • CVE-2016-10752
    40Planlayın

    serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles a

    KritikCVSS 9,8İstismar yokEPSS %2

    s9y · serendipity24 May 2019

  • CVE-2005-1449
    40Planlayın

    Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.

    KritikCVSS 10,0İstismar yokEPSS %1

    s9y · serendipity3 May 2005

  • CVE-2005-1452
    40Planlayın

    Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."

    KritikCVSS 10,0İstismar yokEPSS %1

    s9y · serendipity3 May 2005

  • CVE-2017-5609
    35İzleyin

    SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary

    YüksekCVSS 8,8İstismar yokEPSS %2

    s9y · serendipity28 Oca 2017

  • CVE-2023-31576
    35İzleyin

    An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript

    YüksekCVSS 8,8İstismar yokEPSS %1

    s9y · serendipity16 May 2023

  • CVE-2017-5476
    35İzleyin

    Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.

    YüksekCVSS 8,8İstismar yokEPSS %1

    s9y · serendipity14 Oca 2017

  • CVE-2017-8101
    35İzleyin

    There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

    YüksekCVSS 8,8İstismar yokEPSS %1

    s9y · serendipity24 Nis 2017

  • CVE-2017-5475
    35İzleyin

    comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.

    YüksekCVSS 8,8İstismar yokEPSS %1

    s9y · serendipity14 Oca 2017

  • CVE-2016-9752
    34İzleyin

    In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redir

    YüksekCVSS 8,6İstismar yokEPSS %1

    s9y · serendipity1 Ara 2016

  • CVE-2024-58282
    34İzleyin

    Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload

    YüksekCVSS 8,6İstismar yokEPSS %1

    s9y · serendipity10 Ara 2025

  • CVE-2023-53933
    34İzleyin

    Serendipity 2.4.0 Authenticated Remote Code Execution via File Upload

    YüksekCVSS 8,7İstismar yokEPSS %1

    s9y · serendipity17 Ara 2025

  • CVE-2004-2158
    31İzleyin

    SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    s9y · serendipity31 Ara 2004

  • CVE-2010-1916
    31İzleyin

    The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote a

    YüksekCVSS 7,5İstismar yokEPSS %3

    xinha · wysiwyg editor12 May 2010

  • CVE-2012-2762
    31İzleyin

    SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL co

    YüksekCVSS 7,5İstismar yokEPSS %2

    s9y · serendipity7 Haz 2012

  • CVE-2005-1134
    31İzleyin

    SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    s9y · serendipity13 Nis 2005

  • CVE-2012-2332
    30İzleyin

    SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQ

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    s9y · serendipity13 Ağu 2012

  • CVE-2005-1451
    30İzleyin

    The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.

    YüksekCVSS 7,5İstismar yokEPSS %2

    s9y · serendipity3 May 2005

  • CVE-2006-2495
    30İzleyin

    Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unau

    YüksekCVSS 7,5İstismar yokEPSS %2

    s9y · serendipity19 May 2006

  • CVE-2006-1910
    30İzleyin

    config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.ph

    YüksekCVSS 7,5İstismar yokEPSS %1

    s9y · serendipity20 Nis 2006

  • CVE-2009-3337
    30İzleyin

    SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to e

    YüksekCVSS 7,5İstismar yokEPSS %1

    s9y · serendipity event freetag24 Eyl 2009

  • CVE-2005-1450
    30İzleyin

    Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.

    YüksekCVSS 7,5İstismar yokEPSS %1

    s9y · serendipity3 May 2005

  • Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %1

    s9y · serendipity17 Kas 2017