Skip to content
Noroxi

eprints records

6 published records for vendor eprints.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex

    CriticalCVSS 9.8No exploitEPSS 4%

    eprints · eprintsMar 1, 2021

  • EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase

    CriticalCVSS 9.8No exploitEPSS 4%

    eprints · eprintsMar 1, 2021

  • EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

    CriticalCVSS 9.8No exploitEPSS 3%

    eprints · eprintsMar 1, 2021

  • EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

    HighCVSS 8.8No exploitEPSS 3%

    eprints · eprintsMar 1, 2021

  • EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

    MediumCVSS 6.1Proof of conceptEPSS 7%

    eprints · eprintsMar 1, 2021

  • EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.

    MediumCVSS 6.1Proof of conceptEPSS 3%

    eprints · eprintsMar 1, 2021