Skip to content
Noroxi

timgreen records

8 published records for vendor timgreen.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    timgreen · python bookNov 15, 2024

  • dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.

    CriticalCVSS 9.3No exploitEPSS 0%

    timgreen · dingfanzu cmsNov 8, 2024

  • python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different I

    HighCVSS 7.5No exploitEPSS 1%

    timgreen · python bookNov 15, 2024

  • dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

    MediumCVSS 6.3No exploitEPSS 0%

    timgreen · dingfanzu cmsSep 25, 2024

  • dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=1

    MediumCVSS 6.3No exploitEPSS 0%

    timgreen · dingfanzu cmsOct 28, 2024

  • dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

    MediumCVSS 6.3No exploitEPSS 0%

    timgreen · dingfanzu cmsOct 28, 2024

  • dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php

    MediumCVSS 6.1No exploitEPSS 0%

    timgreen · dingfanzu cmsOct 16, 2024

  • dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

    MediumCVSS 4.7No exploitEPSS 0%

    timgreen · dingfanzu cmsSep 25, 2024