sawmill kayıtları
sawmill üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-310 Cryptographic Issues1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-5496Kavram kanıtı | Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.sawmill · sawmill · CWE-200 | Kritik9,8 | — | %5,8 | 15 Mar 2017 |
31İzleyin | CVE-2000-0589Kavram kanıtı | SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configusawmill · sawmill · CWE-310 | Yüksek7,5 | — | %3,7 | 26 Haz 2000 |
31İzleyin | CVE-2005-1900İstismar yok | Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.sawmill · sawmill | Yüksek7,5 | — | %2,1 | 9 Haz 2005 |
30İzleyin | CVE-2013-4947İstismar yok | Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and asawmill · sawmill | Yüksek7,5 | — | %1,5 | 29 Tem 2013 |
22İzleyin | CVE-2000-0588Kavram kanıtı | SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whossawmill · sawmill · CWE-200 | Orta5,0 | — | %7,5 | 26 Haz 2000 |
18İzleyin | CVE-2002-0265Kavram kanıtı | Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privsawmill · sawmill | Orta4,6 | — | %0,8 | 29 May 2002 |
17İzleyin | CVE-2005-2950İstismar yok | Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via sawmill · sawmill | Orta4,3 | — | %1,4 | 16 Eyl 2005 |
17İzleyin | CVE-2005-1901İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML visawmill · sawmill | Orta4,3 | — | %1,4 | 9 Haz 2005 |
17İzleyin | CVE-2010-1079İstismar yok | Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecisawmill · sawmill · CWE-79 | Orta4,3 | — | %1,0 | 23 Mar 2010 |
- CVE-2017-549641Planlayın
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
KritikCVSS 9,8Kavram kanıtıEPSS %6sawmill · sawmill15 Mar 2017
- CVE-2000-058931İzleyin
SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configu
YüksekCVSS 7,5Kavram kanıtıEPSS %4sawmill · sawmill26 Haz 2000
- CVE-2005-190031İzleyin
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.
YüksekCVSS 7,5İstismar yokEPSS %2sawmill · sawmill9 Haz 2005
- CVE-2013-494730İzleyin
Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and a
YüksekCVSS 7,5İstismar yokEPSS %2sawmill · sawmill29 Tem 2013
- CVE-2000-058822İzleyin
SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whos
OrtaCVSS 5,0Kavram kanıtıEPSS %7sawmill · sawmill26 Haz 2000
- CVE-2002-026518İzleyin
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain priv
OrtaCVSS 4,6Kavram kanıtıEPSS %1sawmill · sawmill29 May 2002
- CVE-2005-295017İzleyin
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %1sawmill · sawmill16 Eyl 2005
- CVE-2005-190117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 4,3İstismar yokEPSS %1sawmill · sawmill9 Haz 2005
- CVE-2010-107917İzleyin
Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspeci
OrtaCVSS 4,3İstismar yokEPSS %1sawmill · sawmill23 Mar 2010