Записи bigtreecms
45 опубликованных записей вендора bigtreecms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
45 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-10574Эксплойта нет | site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the Bbigtreecms · bigtree cms · CWE-94 | Критическая9,8 | — | 2,2 % | 30 апр. 2018 г. |
40В плане | CVE-2017-7695Эксплойта нет | Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety chbigtreecms · bigtree cms · CWE-434 | Критическая9,8 | — | 2,0 % | 11 апр. 2017 г. |
39Наблюдать | CVE-2017-9364Эксплойта нет | Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a bigtreecms · bigtree cms · CWE-434 | Критическая9,8 | — | 1,3 % | 2 июн. 2017 г. |
36Наблюдать | CVE-2017-9442Эксплойта нет | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web sbigtreecms · bigtree cms · CWE-94 | Высокая8,8 | — | 2,5 % | 5 июн. 2017 г. |
36Наблюдать | CVE-2020-26670Эксплойта нет | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands tbigtreecms · bigtree cms · CWE-78 | Высокая8,8 | — | 1,8 % | 1 июн. 2021 г. |
35Наблюдать | CVE-2017-9427Эксплойта нет | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\adminbigtreecms · bigtree cms · CWE-89 | Высокая8,8 | — | 1,6 % | 4 июн. 2017 г. |
35Наблюдать | CVE-2020-26668Эксплойта нет | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacbigtreecms · bigtree cms · CWE-89 | Высокая8,8 | — | 1,4 % | 1 июн. 2021 г. |
35Наблюдать | CVE-2017-9443Эксплойта нет | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json ibigtreecms · bigtree cms · CWE-89 | Высокая8,8 | — | 1,3 % | 5 июн. 2017 г. |
35Наблюдать | CVE-2017-9449Эксплойта нет | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/adminbigtreecms · bigtree cms · CWE-89 | Высокая8,8 | — | 1,1 % | 6 июн. 2017 г. |
35Наблюдать | CVE-2017-11736Эксплойта нет | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbibigtreecms · bigtree cms · CWE-89 | Высокая8,8 | — | 1,0 % | 29 июл. 2017 г. |
35Наблюдать | CVE-2017-7881Эксплойта нет | BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing thbigtreecms · bigtree cms · CWE-352 | Высокая8,8 | — | 0,8 % | 15 апр. 2017 г. |
35Наблюдать | CVE-2017-9365Эксплойта нет | CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fobigtreecms · bigtree cms · CWE-352 | Высокая8,8 | — | 0,5 % | 2 июн. 2017 г. |
35Наблюдать | CVE-2017-9379Эксплойта нет | Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.pbigtreecms · bigtree cms · CWE-352 | Высокая8,8 | — | 0,5 % | 2 июн. 2017 г. |
35Наблюдать | CVE-2017-9444Эксплойта нет | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.pbigtreecms · bigtree cms · CWE-352 | Высокая8,8 | — | 0,5 % | 5 июн. 2017 г. |
33Наблюдать | CVE-2018-17341Эксплойта нет | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ subigtreecms · bigtree cms · CWE-287 | Высокая8,1 | — | 1,9 % | 23 сент. 2018 г. |
31Наблюдать | CVE-2013-4879Proof of concept | SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL bigtreecms · bigtree cms · CWE-89 | Высокая7,5 | — | 2,3 % | 14 авг. 2013 г. |
31Наблюдать | CVE-2018-17030Эксплойта нет | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-bigtreecms · bigtree cms · CWE-94 | Высокая7,5 | — | 2,3 % | 13 сент. 2018 г. |
31Наблюдать | CVE-2017-9428Эксплойта нет | A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windowsbigtreecms · bigtree cms · CWE-22 | Высокая7,5 | — | 2,0 % | 4 июн. 2017 г. |
28Наблюдать | CVE-2013-4881Proof of concept | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Средняя6,8 | — | 2,2 % | 19 авг. 2013 г. |
28Наблюдать | CVE-2017-6914Эксплойта нет | CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.bigtreecms · bigtree cms · CWE-352 | Высокая7,1 | — | 0,4 % | 15 мар. 2017 г. |
27Наблюдать | CVE-2013-5313Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Средняя6,8 | — | 0,9 % | 19 авг. 2013 г. |
26Наблюдать | CVE-2017-16961Эксплойта нет | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain infbigtreecms · bigtree cms · CWE-89 | Средняя6,5 | — | 1,4 % | 27 нояб. 2017 г. |
26Наблюдать | CVE-2017-9378Эксплойта нет | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.bigtreecms · bigtree cms · CWE-863 | Средняя6,5 | — | 0,6 % | 2 июн. 2017 г. |
25Наблюдать | CVE-2018-18308Proof of concept | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload abigtreecms · bigtree cms · CWE-79 | Средняя6,1 | — | 3,6 % | 16 окт. 2018 г. |
24Наблюдать | CVE-2018-1000521Эксплойта нет | BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vubigtreecms · bigtree cms · CWE-79 | Средняя6,1 | — | 0,9 % | 26 июн. 2018 г. |
- CVE-2018-1057440В плане
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bigtreecms · bigtree cms30 апр. 2018 г.
- CVE-2017-769540В плане
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bigtreecms · bigtree cms11 апр. 2017 г.
- CVE-2017-936439Наблюдать
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms2 июн. 2017 г.
- CVE-2017-944236Наблюдать
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bigtreecms · bigtree cms5 июн. 2017 г.
- CVE-2020-2667036Наблюдать
A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bigtreecms · bigtree cms1 июн. 2021 г.
- CVE-2017-942735Наблюдать
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bigtreecms · bigtree cms4 июн. 2017 г.
- CVE-2020-2666835Наблюдать
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms1 июн. 2021 г.
- CVE-2017-944335Наблюдать
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms5 июн. 2017 г.
- CVE-2017-944935Наблюдать
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms6 июн. 2017 г.
- CVE-2017-1173635Наблюдать
SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms29 июл. 2017 г.
- CVE-2017-788135Наблюдать
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms15 апр. 2017 г.
- CVE-2017-936535Наблюдать
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bigtreecms · bigtree cms2 июн. 2017 г.
- CVE-2017-937935Наблюдать
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bigtreecms · bigtree cms2 июн. 2017 г.
- CVE-2017-944435Наблюдать
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bigtreecms · bigtree cms5 июн. 2017 г.
- CVE-2018-1734133Наблюдать
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %bigtreecms · bigtree cms23 сент. 2018 г.
- CVE-2013-487931Наблюдать
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %bigtreecms · bigtree cms14 авг. 2013 г.
- CVE-2018-1703031Наблюдать
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bigtreecms · bigtree cms13 сент. 2018 г.
- CVE-2017-942831Наблюдать
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bigtreecms · bigtree cms4 июн. 2017 г.
- CVE-2013-488128Наблюдать
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
СредняяCVSS 6,8Proof of conceptEPSS 2 %bigtreecms · bigtree cms19 авг. 2013 г.
- CVE-2017-691428Наблюдать
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %bigtreecms · bigtree cms15 мар. 2017 г.
- CVE-2013-531327Наблюдать
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
СредняяCVSS 6,8Эксплойта нетEPSS 1 %bigtreecms · bigtree cms19 авг. 2013 г.
- CVE-2017-1696126Наблюдать
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bigtreecms · bigtree cms27 нояб. 2017 г.
- CVE-2017-937826Наблюдать
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bigtreecms · bigtree cms2 июн. 2017 г.
- CVE-2018-1830825Наблюдать
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a
СредняяCVSS 6,1Proof of conceptEPSS 4 %bigtreecms · bigtree cms16 окт. 2018 г.
- CVE-2018-100052124Наблюдать
BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigtreecms · bigtree cms26 июн. 2018 г.