Записи clippercms
10 опубликованных записей вендора clippercms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-384 Session Fixation1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-41495Эксплойта нет | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.clippercms · clippercms · CWE-918 | Критическая9,8 | — | 1,0 % | 13 окт. 2022 г. |
39Наблюдать | CVE-2022-41497Эксплойта нет | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.clippercms · clippercms · CWE-918 | Критическая9,8 | — | 1,0 % | 13 окт. 2022 г. |
36Наблюдать | CVE-2018-19135Proof of concept | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).clippercms · clippercms · CWE-352 | Высокая8,8 | — | 3,0 % | 11 нояб. 2018 г. |
35Наблюдать | CVE-2018-11571Эксплойта нет | ClipperCMS 1.3.3 allows Session Fixation.clippercms · clippercms · CWE-384 | Высокая8,8 | — | 1,3 % | 30 мая 2018 г. |
29Наблюдать | CVE-2018-19424Эксплойта нет | ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.clippercms · clippercms · CWE-434 | Высокая7,2 | — | 1,8 % | 21 нояб. 2018 г. |
21Наблюдать | CVE-2018-12101Эксплойта нет | CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.clippercms · clippercms · CWE-79 | Средняя5,4 | — | 1,3 % | 15 авг. 2019 г. |
21Наблюдать | CVE-2018-11572Эксплойта нет | ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.clippercms · clippercms · CWE-79 | Средняя5,4 | — | 0,7 % | 30 мая 2018 г. |
20Наблюдать | CVE-2018-11332Proof of concept | Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 alclippercms · clippercms · CWE-79 | Средняя4,8 | — | 1,9 % | 24 мая 2018 г. |
19Наблюдать | CVE-2018-13998Эксплойта нет | ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.clippercms · clippercms · CWE-79 | Средняя4,8 | — | 0,7 % | 12 июл. 2018 г. |
19Наблюдать | CVE-2018-13106Эксплойта нет | ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.clippercms · clippercms · CWE-79 | Средняя4,8 | — | 0,7 % | 3 июл. 2018 г. |
- CVE-2022-4149539Наблюдать
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clippercms · clippercms13 окт. 2022 г.
- CVE-2022-4149739Наблюдать
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clippercms · clippercms13 окт. 2022 г.
- CVE-2018-1913536Наблюдать
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %clippercms · clippercms11 нояб. 2018 г.
- CVE-2018-1157135Наблюдать
ClipperCMS 1.3.3 allows Session Fixation.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %clippercms · clippercms30 мая 2018 г.
- CVE-2018-1942429Наблюдать
ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %clippercms · clippercms21 нояб. 2018 г.
- CVE-2018-1210121Наблюдать
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %clippercms · clippercms15 авг. 2019 г.
- CVE-2018-1157221Наблюдать
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %clippercms · clippercms30 мая 2018 г.
- CVE-2018-1133220Наблюдать
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 al
СредняяCVSS 4,8Proof of conceptEPSS 2 %clippercms · clippercms24 мая 2018 г.
- CVE-2018-1399819Наблюдать
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %clippercms · clippercms12 июл. 2018 г.
- CVE-2018-1310619Наблюдать
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %clippercms · clippercms3 июл. 2018 г.