xpressengine kayıtları
xpressengine üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %40
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-26642İstismar yok | XpressEngine file upload vulnerabilityxpressengine · xpressengine · CWE-434 | Kritik9,8 | — | %1,2 | 20 Oca 2023 |
39İzleyin | CVE-2011-10003İstismar yok | XpressEngine Update Query sql injectionxpressengine · xpressengine · CWE-89 | Kritik9,8 | — | %0,6 | 7 Şub 2023 |
28İzleyin | CVE-2009-4834Kavram kanıtı | lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_conxpressengine · zeroboard · CWE-94 | Orta6,8 | — | %4,0 | 4 May 2010 |
21İzleyin | CVE-2021-44911İstismar yok | XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php.xpressengine · xpressengine · CWE-79 | Orta5,4 | — | %0,6 | 9 Şub 2022 |
21İzleyin | CVE-2021-44912İstismar yok | In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files dixpressengine · xpressengine · CWE-79 | Orta5,4 | — | %0,5 | 9 Şub 2022 |
- CVE-2021-2664239İzleyin
XpressEngine file upload vulnerability
KritikCVSS 9,8İstismar yokEPSS %1xpressengine · xpressengine20 Oca 2023
- CVE-2011-1000339İzleyin
XpressEngine Update Query sql injection
KritikCVSS 9,8İstismar yokEPSS %1xpressengine · xpressengine7 Şub 2023
- CVE-2009-483428İzleyin
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_con
OrtaCVSS 6,8Kavram kanıtıEPSS %4xpressengine · zeroboard4 May 2010
- CVE-2021-4491121İzleyin
XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php.
OrtaCVSS 5,4İstismar yokEPSS %1xpressengine · xpressengine9 Şub 2022
- CVE-2021-4491221İzleyin
In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files di
OrtaCVSS 5,4İstismar yokEPSS %0xpressengine · xpressengine9 Şub 2022