eprints records
6 published records for vendor eprints.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-3342No exploit | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latexeprints · eprints · CWE-78 | Critical9.8 | — | 4.2% | Mar 1, 2021 |
40Plan | CVE-2021-26703No exploit | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase eprints · eprints · CWE-611 | Critical9.8 | — | 4.0% | Mar 1, 2021 |
40Plan | CVE-2021-26476No exploit | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.eprints · eprints · CWE-78 | Critical9.8 | — | 3.1% | Mar 1, 2021 |
36Monitor | CVE-2021-26704No exploit | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.eprints · eprints · CWE-78 | High8.8 | — | 3.1% | Mar 1, 2021 |
26Monitor | CVE-2021-26475Proof of concept | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.eprints · eprints · CWE-79 | Medium6.1 | — | 7.3% | Mar 1, 2021 |
25Monitor | CVE-2021-26702Proof of concept | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.eprints · eprints · CWE-79 | Medium6.1 | — | 3.1% | Mar 1, 2021 |
- CVE-2021-334240Plan
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex
CriticalCVSS 9.8No exploitEPSS 4%eprints · eprintsMar 1, 2021
- CVE-2021-2670340Plan
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase
CriticalCVSS 9.8No exploitEPSS 4%eprints · eprintsMar 1, 2021
- CVE-2021-2647640Plan
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
CriticalCVSS 9.8No exploitEPSS 3%eprints · eprintsMar 1, 2021
- CVE-2021-2670436Monitor
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
HighCVSS 8.8No exploitEPSS 3%eprints · eprintsMar 1, 2021
- CVE-2021-2647526Monitor
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
MediumCVSS 6.1Proof of conceptEPSS 7%eprints · eprintsMar 1, 2021
- CVE-2021-2670225Monitor
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
MediumCVSS 6.1Proof of conceptEPSS 3%eprints · eprintsMar 1, 2021