Записи Biscom
7 опубликованных записей вендора biscom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 28,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-8796Эксплойта нет | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.biscom · secure file transfer | Критическая9,8 | — | 2,9 % | 7 февр. 2020 г. |
32Наблюдать | CVE-2016-10710Эксплойта нет | Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allobiscom · secure file transfer · CWE-20 | Высокая8,1 | — | 1,1 % | 25 янв. 2018 г. |
26Наблюдать | CVE-2020-27646Эксплойта нет | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.biscom · secure file transfer | Средняя6,5 | — | 1,0 % | 22 окт. 2020 г. |
26Наблюдать | CVE-2020-8503Эксплойта нет | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by biscom · secure file transfer · CWE-639 | Средняя6,5 | — | 0,7 % | 31 янв. 2020 г. |
21Наблюдать | CVE-2017-5241Эксплойта нет | Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in biscom · secure file transfer · CWE-79 | Средняя5,4 | — | 0,9 % | 28 июн. 2017 г. |
21Наблюдать | CVE-2017-5247Эксплойта нет | Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field.biscom · secure file transfer · CWE-79 | Средняя5,4 | — | 0,5 % | 18 июл. 2017 г. |
17Наблюдать | CVE-2017-5246Эксплойта нет | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.biscom · secure file transfer · CWE-74 | Средняя4,3 | — | 0,6 % | 18 июл. 2017 г. |
- CVE-2020-879640В плане
Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %biscom · secure file transfer7 февр. 2020 г.
- CVE-2016-1071032Наблюдать
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allo
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %biscom · secure file transfer25 янв. 2018 г.
- CVE-2020-2764626Наблюдать
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %biscom · secure file transfer22 окт. 2020 г.
- CVE-2020-850326Наблюдать
Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by
СредняяCVSS 6,5Эксплойта нетEPSS 1 %biscom · secure file transfer31 янв. 2020 г.
- CVE-2017-524121Наблюдать
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in
СредняяCVSS 5,4Эксплойта нетEPSS 1 %biscom · secure file transfer28 июн. 2017 г.
- CVE-2017-524721Наблюдать
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %biscom · secure file transfer18 июл. 2017 г.
- CVE-2017-524617Наблюдать
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %biscom · secure file transfer18 июл. 2017 г.