Записи 5none
12 опубликованных записей вендора 5none.
Профиль для исследователя
- Попали в KEV
- 1 · 8,3 %
- С эксплойтом
- 1 · 8,3 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 1058 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2018-20062Готовый эксплойт | An issue was discovered in NoneCms V1.3.5none · nonecms | Критическая9,8 | KEV | 99,5 % | 11 дек. 2018 г. |
35Наблюдать | CVE-2018-7219Эксплойта нет | application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p5none · nonecms · CWE-352 | Высокая8,8 | — | 0,5 % | 19 февр. 2018 г. |
30Наблюдать | CVE-2020-18646Эксплойта нет | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".5none · nonecms · CWE-668 | Высокая7,5 | — | 1,5 % | 22 июн. 2021 г. |
30Наблюдать | CVE-2020-18647Эксплойта нет | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".5none · nonecms · CWE-668 | Высокая7,5 | — | 1,5 % | 22 июн. 2021 г. |
30Наблюдать | CVE-2018-6029Эксплойта нет | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and5none · nonecms · CWE-918 | Высокая7,5 | — | 1,4 % | 23 янв. 2018 г. |
26Наблюдать | CVE-2018-6022Эксплойта нет | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del5none · nonecms · CWE-22 | Средняя6,5 | — | 1,4 % | 23 янв. 2018 г. |
26Наблюдать | CVE-2019-16721Эксплойта нет | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.5none · nonecms · CWE-352 | Средняя6,5 | — | 0,5 % | 23 сент. 2019 г. |
24Наблюдать | CVE-2020-23371Эксплойта нет | Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo5none · nonecms · CWE-79 | Средняя6,1 | — | 0,9 % | 10 мая 2021 г. |
24Наблюдать | CVE-2020-18282Эксплойта нет | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur5none · nonecms · CWE-79 | Средняя6,1 | — | 0,5 % | 8 мая 2023 г. |
24Наблюдать | CVE-2020-23376Эксплойта нет | NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj5none · nonecms · CWE-352 | Средняя6,1 | — | 0,4 % | 10 мая 2021 г. |
21Наблюдать | CVE-2020-23373Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w5none · nonecms · CWE-79 | Средняя5,4 | — | 0,8 % | 10 мая 2021 г. |
21Наблюдать | CVE-2020-23374Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra5none · nonecms · CWE-79 | Средняя5,4 | — | 0,8 % | 10 мая 2021 г. |
- CVE-2018-2006299Срочно
An issue was discovered in NoneCms V1.3.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %5none · nonecms11 дек. 2018 г.
- CVE-2018-721935Наблюдать
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %5none · nonecms19 февр. 2018 г.
- CVE-2020-1864630Наблюдать
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %5none · nonecms22 июн. 2021 г.
- CVE-2020-1864730Наблюдать
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %5none · nonecms22 июн. 2021 г.
- CVE-2018-602930Наблюдать
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %5none · nonecms23 янв. 2018 г.
- CVE-2018-602226Наблюдать
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del
СредняяCVSS 6,5Эксплойта нетEPSS 1 %5none · nonecms23 янв. 2018 г.
- CVE-2019-1672126Наблюдать
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %5none · nonecms23 сент. 2019 г.
- CVE-2020-2337124Наблюдать
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo
СредняяCVSS 6,1Эксплойта нетEPSS 1 %5none · nonecms10 мая 2021 г.
- CVE-2020-1828224Наблюдать
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur
СредняяCVSS 6,1Эксплойта нетEPSS 1 %5none · nonecms8 мая 2023 г.
- CVE-2020-2337624Наблюдать
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj
СредняяCVSS 6,1Эксплойта нетEPSS 0 %5none · nonecms10 мая 2021 г.
- CVE-2020-2337321Наблюдать
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w
СредняяCVSS 5,4Эксплойта нетEPSS 1 %5none · nonecms10 мая 2021 г.
- CVE-2020-2337421Наблюдать
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra
СредняяCVSS 5,4Эксплойта нетEPSS 1 %5none · nonecms10 мая 2021 г.