Tecnick kayıtları
tecnick üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %7,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2018-17057Kavram kanıtı | An issue was discovered in TCPDF before 6.2.22.tecnick · tcpdf · CWE-502 | Kritik9,8 | — | %26,2 | 14 Eyl 2018 |
32İzleyin | CVE-2021-20114Kavram kanıtı | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directecnick · tcexam · CWE-425 | Yüksek7,5 | — | %6,0 | 30 Tem 2021 |
31İzleyin | CVE-2009-4747Kavram kanıtı | PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attatecnick · aiocp · CWE-94 | Yüksek7,5 | — | %3,0 | 26 Mar 2010 |
31İzleyin | CVE-2009-3220Kavram kanıtı | PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute artecnick · aiocp · CWE-94 | Yüksek7,5 | — | %2,1 | 16 Eyl 2009 |
29İzleyin | CVE-2010-2153Kavram kanıtı | Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackertecnick · tcexam | Orta6,8 | — | %7,5 | 3 Haz 2010 |
29İzleyin | CVE-2020-5745İstismar yok | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users itecnick · tcexam · CWE-352 | Yüksek7,4 | — | %0,8 | 7 May 2020 |
28İzleyin | CVE-2012-4237Kavram kanıtı | Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exetecnick · tcexam · CWE-89 | Orta6,8 | — | %2,4 | 20 Ağu 2012 |
26İzleyin | CVE-2023-6554İstismar yok | Missing authorisation in TCExamtecnick · tcexam · CWE-862 | Orta6,5 | — | %0,6 | 11 Oca 2024 |
24İzleyin | CVE-2012-4601İstismar yok | Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permitecnick · tcexam · CWE-89 | Orta6,0 | — | %1,6 | 23 Kas 2012 |
24İzleyin | CVE-2020-5750İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Orta6,1 | — | %1,1 | 7 May 2020 |
24İzleyin | CVE-2020-5748İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Orta6,1 | — | %1,1 | 7 May 2020 |
24İzleyin | CVE-2021-20115İstismar yok | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.tecnick · tcexam · CWE-79 | Orta6,1 | — | %0,9 | 5 Ağu 2021 |
24İzleyin | CVE-2021-20116İstismar yok | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.tecnick · tcexam · CWE-79 | Orta6,1 | — | %0,9 | 5 Ağu 2021 |
24İzleyin | CVE-2018-13422İstismar yok | TCExam before 14.1.2 has XSS via an ff_ or xl_ field.tecnick · tcexam · CWE-79 | Orta6,1 | — | %0,8 | 7 Tem 2018 |
21İzleyin | CVE-2021-20113İstismar yok | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-203 | Orta5,3 | — | %1,3 | 30 Tem 2021 |
21İzleyin | CVE-2020-5747İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Orta5,4 | — | %0,7 | 7 May 2020 |
21İzleyin | CVE-2020-5746İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Orta5,4 | — | %0,7 | 7 May 2020 |
21İzleyin | CVE-2020-5749İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Orta5,4 | — | %0,7 | 7 May 2020 |
21İzleyin | CVE-2020-5751İstismar yok | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Orta5,4 | — | %0,7 | 7 May 2020 |
21İzleyin | CVE-2021-20112İstismar yok | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Orta5,4 | — | %0,6 | 30 Tem 2021 |
21İzleyin | CVE-2021-20111İstismar yok | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Orta5,4 | — | %0,6 | 30 Tem 2021 |
20İzleyin | CVE-2011-3806İstismar yok | TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation tecnick · tcexam · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
19İzleyin | CVE-2020-5744İstismar yok | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.tecnick · tcexam · CWE-22 | Orta4,9 | — | %1,4 | 7 May 2020 |
18İzleyin | CVE-2012-4602İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow retecnick · tcexam · CWE-79 | Orta4,3 | — | %1,8 | 23 Kas 2012 |
17İzleyin | CVE-2020-5743İstismar yok | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they dontecnick · tcexam · CWE-639 | Orta4,3 | — | %0,8 | 7 May 2020 |
- CVE-2018-1705747Planlayın
An issue was discovered in TCPDF before 6.2.22.
KritikCVSS 9,8Kavram kanıtıEPSS %26tecnick · tcpdf14 Eyl 2018
- CVE-2021-2011432İzleyin
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ direc
YüksekCVSS 7,5Kavram kanıtıEPSS %6tecnick · tcexam30 Tem 2021
- CVE-2009-474731İzleyin
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote atta
YüksekCVSS 7,5Kavram kanıtıEPSS %3tecnick · aiocp26 Mar 2010
- CVE-2009-322031İzleyin
PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute ar
YüksekCVSS 7,5Kavram kanıtıEPSS %2tecnick · aiocp16 Eyl 2009
- CVE-2010-215329İzleyin
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attacker
OrtaCVSS 6,8Kavram kanıtıEPSS %7tecnick · tcexam3 Haz 2010
- CVE-2020-574529İzleyin
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users i
YüksekCVSS 7,4İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2012-423728İzleyin
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exe
OrtaCVSS 6,8Kavram kanıtıEPSS %2tecnick · tcexam20 Ağu 2012
- CVE-2023-655426İzleyin
Missing authorisation in TCExam
OrtaCVSS 6,5İstismar yokEPSS %1tecnick · tcexam11 Oca 2024
- CVE-2012-460124İzleyin
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permi
OrtaCVSS 6,0İstismar yokEPSS %2tecnick · tcexam23 Kas 2012
- CVE-2020-575024İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2020-574824İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2021-2011524İzleyin
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.
OrtaCVSS 6,1İstismar yokEPSS %1tecnick · tcexam5 Ağu 2021
- CVE-2021-2011624İzleyin
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.
OrtaCVSS 6,1İstismar yokEPSS %1tecnick · tcexam5 Ağu 2021
- CVE-2018-1342224İzleyin
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
OrtaCVSS 6,1İstismar yokEPSS %1tecnick · tcexam7 Tem 2018
- CVE-2021-2011321İzleyin
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.
OrtaCVSS 5,3İstismar yokEPSS %1tecnick · tcexam30 Tem 2021
- CVE-2020-574721İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2020-574621İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2020-574921İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2020-575121İzleyin
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2021-2011221İzleyin
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam30 Tem 2021
- CVE-2021-2011121İzleyin
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
OrtaCVSS 5,4İstismar yokEPSS %1tecnick · tcexam30 Tem 2021
- CVE-2011-380620İzleyin
TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1tecnick · tcexam23 Eyl 2011
- CVE-2020-574419İzleyin
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
OrtaCVSS 4,9İstismar yokEPSS %1tecnick · tcexam7 May 2020
- CVE-2012-460218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow re
OrtaCVSS 4,3İstismar yokEPSS %2tecnick · tcexam23 Kas 2012
- CVE-2020-574317İzleyin
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don
OrtaCVSS 4,3İstismar yokEPSS %1tecnick · tcexam7 May 2020