Перейти к содержимому
Noroxi

Записи clippercms

10 опубликованных записей вендора clippercms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 18
  2. 19
  3. 22

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

10 записей
  • CVE-2022-41495
    39Наблюдать

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    clippercms · clippercms13 окт. 2022 г.

  • CVE-2022-41497
    39Наблюдать

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    clippercms · clippercms13 окт. 2022 г.

  • CVE-2018-19135
    36Наблюдать

    ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    clippercms · clippercms11 нояб. 2018 г.

  • CVE-2018-11571
    35Наблюдать

    ClipperCMS 1.3.3 allows Session Fixation.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    clippercms · clippercms30 мая 2018 г.

  • CVE-2018-19424
    29Наблюдать

    ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    clippercms · clippercms21 нояб. 2018 г.

  • CVE-2018-12101
    21Наблюдать

    CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    clippercms · clippercms15 авг. 2019 г.

  • CVE-2018-11572
    21Наблюдать

    ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    clippercms · clippercms30 мая 2018 г.

  • CVE-2018-11332
    20Наблюдать

    Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 al

    СредняяCVSS 4,8Proof of conceptEPSS 2 %

    clippercms · clippercms24 мая 2018 г.

  • CVE-2018-13998
    19Наблюдать

    ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    clippercms · clippercms12 июл. 2018 г.

  • CVE-2018-13106
    19Наблюдать

    ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    clippercms · clippercms3 июл. 2018 г.