Skip to content
Noroxi

Biscom records

7 published records for vendor biscom.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
28.6%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

    CriticalCVSS 9.8No exploitEPSS 3%

    biscom · secure file transferFeb 7, 2020

  • Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allo

    HighCVSS 8.1No exploitEPSS 1%

    biscom · secure file transferJan 25, 2018

  • Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.

    MediumCVSS 6.5No exploitEPSS 1%

    biscom · secure file transferOct 22, 2020

  • CVE-2020-8503
    26Monitor

    Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by

    MediumCVSS 6.5No exploitEPSS 1%

    biscom · secure file transferJan 31, 2020

  • CVE-2017-5241
    21Monitor

    Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in

    MediumCVSS 5.4No exploitEPSS 1%

    biscom · secure file transferJun 28, 2017

  • CVE-2017-5247
    21Monitor

    Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field.

    MediumCVSS 5.4No exploitEPSS 1%

    biscom · secure file transferJul 18, 2017

  • CVE-2017-5246
    17Monitor

    Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.

    MediumCVSS 4.3No exploitEPSS 1%

    biscom · secure file transferJul 18, 2017