Biscom records
7 published records for vendor biscom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-8796No exploit | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.biscom · secure file transfer | Critical9.8 | — | 2.9% | Feb 7, 2020 |
32Monitor | CVE-2016-10710No exploit | Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allobiscom · secure file transfer · CWE-20 | High8.1 | — | 1.1% | Jan 25, 2018 |
26Monitor | CVE-2020-27646No exploit | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.biscom · secure file transfer | Medium6.5 | — | 1.0% | Oct 22, 2020 |
26Monitor | CVE-2020-8503No exploit | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by biscom · secure file transfer · CWE-639 | Medium6.5 | — | 0.7% | Jan 31, 2020 |
21Monitor | CVE-2017-5241No exploit | Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in biscom · secure file transfer · CWE-79 | Medium5.4 | — | 0.9% | Jun 28, 2017 |
21Monitor | CVE-2017-5247No exploit | Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field.biscom · secure file transfer · CWE-79 | Medium5.4 | — | 0.5% | Jul 18, 2017 |
17Monitor | CVE-2017-5246No exploit | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.biscom · secure file transfer · CWE-74 | Medium4.3 | — | 0.6% | Jul 18, 2017 |
- CVE-2020-879640Plan
Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.
CriticalCVSS 9.8No exploitEPSS 3%biscom · secure file transferFeb 7, 2020
- CVE-2016-1071032Monitor
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allo
HighCVSS 8.1No exploitEPSS 1%biscom · secure file transferJan 25, 2018
- CVE-2020-2764626Monitor
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
MediumCVSS 6.5No exploitEPSS 1%biscom · secure file transferOct 22, 2020
- CVE-2020-850326Monitor
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by
MediumCVSS 6.5No exploitEPSS 1%biscom · secure file transferJan 31, 2020
- CVE-2017-524121Monitor
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in
MediumCVSS 5.4No exploitEPSS 1%biscom · secure file transferJun 28, 2017
- CVE-2017-524721Monitor
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field.
MediumCVSS 5.4No exploitEPSS 1%biscom · secure file transferJul 18, 2017
- CVE-2017-524617Monitor
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.
MediumCVSS 4.3No exploitEPSS 1%biscom · secure file transferJul 18, 2017