scriptcase records
10 published records for vendor scriptcase.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-8940No exploit | Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcasescriptcase · scriptcase · CWE-434 | Critical9.8 | — | 0.5% | Sep 24, 2024 |
32Monitor | CVE-2024-46084No exploit | Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.scriptcase · scriptcase · CWE-77 | High8.0 | — | 0.8% | Oct 1, 2024 |
32Monitor | CVE-2024-46080No exploit | Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.scriptcase · scriptcase · CWE-94 | High8.0 | — | 0.8% | Oct 1, 2024 |
32Monitor | CVE-2024-8942No exploit | Cross-site Scripting vulnerability on Scriptcasescriptcase · scriptcase · CWE-79 | High8.2 | — | 0.3% | Sep 24, 2024 |
26Monitor | CVE-2022-32199Proof of concept | db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the scriptcase · scriptcase · CWE-22 | Medium6.5 | — | 1.7% | Mar 27, 2023 |
24Monitor | CVE-2024-46079No exploit | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.scriptcase · scriptcase · CWE-79 | Medium6.1 | — | 0.3% | Oct 1, 2024 |
21Monitor | CVE-2024-8941No exploit | Path Traversal vulnerability on Scriptcasescriptcase · scriptcase · CWE-22 | Medium5.3 | — | 0.6% | Sep 24, 2024 |
21Monitor | CVE-2024-46081No exploit | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS).scriptcase · scriptcase · CWE-79 | Medium5.4 | — | 0.3% | Oct 1, 2024 |
21Monitor | CVE-2024-46082No exploit | Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.scriptcase · scriptcase · CWE-79 | Medium5.4 | — | 0.3% | Oct 1, 2024 |
21Monitor | CVE-2024-46083No exploit | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS).scriptcase · scriptcase · CWE-79 | Medium5.4 | — | 0.3% | Oct 1, 2024 |
- CVE-2024-894039Monitor
Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcase
CriticalCVSS 9.8No exploitEPSS 1%scriptcase · scriptcaseSep 24, 2024
- CVE-2024-4608432Monitor
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
HighCVSS 8.0No exploitEPSS 1%scriptcase · scriptcaseOct 1, 2024
- CVE-2024-4608032Monitor
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
HighCVSS 8.0No exploitEPSS 1%scriptcase · scriptcaseOct 1, 2024
- CVE-2024-894232Monitor
Cross-site Scripting vulnerability on Scriptcase
HighCVSS 8.2No exploitEPSS 0%scriptcase · scriptcaseSep 24, 2024
- CVE-2022-3219926Monitor
db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the
MediumCVSS 6.5Proof of conceptEPSS 2%scriptcase · scriptcaseMar 27, 2023
- CVE-2024-4607924Monitor
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
MediumCVSS 6.1No exploitEPSS 0%scriptcase · scriptcaseOct 1, 2024
- CVE-2024-894121Monitor
Path Traversal vulnerability on Scriptcase
MediumCVSS 5.3No exploitEPSS 1%scriptcase · scriptcaseSep 24, 2024
- CVE-2024-4608121Monitor
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS).
MediumCVSS 5.4No exploitEPSS 0%scriptcase · scriptcaseOct 1, 2024
- CVE-2024-4608221Monitor
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.
MediumCVSS 5.4No exploitEPSS 0%scriptcase · scriptcaseOct 1, 2024
- CVE-2024-4608321Monitor
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS).
MediumCVSS 5.4No exploitEPSS 0%scriptcase · scriptcaseOct 1, 2024