İçeriğe atla
Noroxi

Zikula kayıtları

zikula üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2014-2293
    40Planlayın

    Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary file

    KritikCVSS 9,8İstismar yokEPSS %5

    zikula · zikula application framework26 Mar 2018

  • CVE-2016-9835
    40Planlayın

    Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacke

    KritikCVSS 9,8İstismar yokEPSS %4

    zikula · zikula application framework5 Ara 2016

  • CVE-2011-0535
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authenticat

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    zikula · zikula application framework8 Şub 2011

  • CVE-2010-4729
    27İzleyin

    Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it

    OrtaCVSS 6,8İstismar yokEPSS %1

    zikula · zikula application framework8 Şub 2011

  • CVE-2010-1732
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to

    OrtaCVSS 6,8İstismar yokEPSS %1

    zikula · zikula application framework6 May 2010

  • CVE-2011-3826
    20İzleyin

    Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat

    OrtaCVSS 5,0İstismar yokEPSS %1

    zikula · zikula23 Eyl 2011

  • CVE-2010-4728
    20İzleyin

    Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat

    OrtaCVSS 5,0İstismar yokEPSS %1

    zikula · zikula application framework8 Şub 2011

  • CVE-2011-3979
    18İzleyin

    Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    zikula · zikula application framework4 Eki 2011

  • CVE-2010-1724
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to i

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    zikula · zikula application framework6 May 2010

  • CVE-2013-6168
    17İzleyin

    Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script

    OrtaCVSS 4,3İstismar yokEPSS %1

    zikula · zikula application framework14 Kas 2013

  • CVE-2011-0911
    17İzleyin

    Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script o

    OrtaCVSS 4,3İstismar yokEPSS %1

    zikula · zikula application framework8 Şub 2011