wallaceit kayıtları
wallaceit üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2019-3959İstismar yok | Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate userwallaceit · wallacepos · CWE-352 | Yüksek8,8 | — | %0,8 | 31 Tem 2019 |
29İzleyin | CVE-2019-3960İstismar yok | Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uplwallaceit · wallacepos · CWE-434 | Yüksek7,2 | — | %3,0 | 31 Tem 2019 |
24İzleyin | CVE-2017-7388İstismar yok | A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'.wallaceit · wallacepos · CWE-79 | Orta6,1 | — | %0,8 | 31 Mar 2017 |
21İzleyin | CVE-2019-3958İstismar yok | Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSSwallaceit · wallacepos · CWE-79 | Orta5,4 | — | %0,9 | 31 Tem 2019 |
- CVE-2019-395935İzleyin
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate user
YüksekCVSS 8,8İstismar yokEPSS %1wallaceit · wallacepos31 Tem 2019
- CVE-2019-396029İzleyin
Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by upl
YüksekCVSS 7,2İstismar yokEPSS %3wallaceit · wallacepos31 Tem 2019
- CVE-2017-738824İzleyin
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'.
OrtaCVSS 6,1İstismar yokEPSS %1wallaceit · wallacepos31 Mar 2017
- CVE-2019-395821İzleyin
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS
OrtaCVSS 5,4İstismar yokEPSS %1wallaceit · wallacepos31 Tem 2019