Записи comsenz
9 опубликованных записей вендора comsenz.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-18083Эксплойта нет | An issue was discovered in DuomiCMS 3.0.comsenz · duomicms · CWE-94 | Критическая9,8 | — | 2,5 % | 9 окт. 2018 г. |
39Наблюдать | CVE-2018-18084Эксплойта нет | An issue was discovered in DuomiCMS 3.0.comsenz · duomicms · CWE-89 | Критическая9,8 | — | 1,3 % | 9 окт. 2018 г. |
38Наблюдать | CVE-2018-14729Proof of concept | The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP comsenz · discuz\! · CWE-20 | Высокая8,8 | — | 10,4 % | 22 мая 2019 г. |
32Наблюдать | CVE-2018-20422Эксплойта нет | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#commoncomsenz · discuzx · CWE-287 | Высокая8,1 | — | 1,3 % | 24 дек. 2018 г. |
32Наблюдать | CVE-2018-20423Эксплойта нет | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existcomsenz · discuzx | Высокая8,1 | — | 1,2 % | 24 дек. 2018 г. |
30Наблюдать | CVE-2008-3554Proof of concept | SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parametcomsenz · discuz · CWE-89 | Высокая7,5 | — | 1,0 % | 8 авг. 2008 г. |
30Наблюдать | CVE-2009-3185Proof of concept | SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQcomsenz · crazy star plugin · CWE-89 | Высокая7,5 | — | 1,0 % | 15 сент. 2009 г. |
28Наблюдать | CVE-2008-6958Proof of concept | wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula pcomsenz · crossday discuz\! board · CWE-94 | Средняя6,5 | — | 5,8 % | 12 авг. 2009 г. |
23Наблюдать | CVE-2018-20424Эксплойта нет | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbcomsenz · discuzx · CWE-20 | Средняя5,9 | — | 0,9 % | 24 дек. 2018 г. |
- CVE-2018-1808340В плане
An issue was discovered in DuomiCMS 3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %comsenz · duomicms9 окт. 2018 г.
- CVE-2018-1808439Наблюдать
An issue was discovered in DuomiCMS 3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %comsenz · duomicms9 окт. 2018 г.
- CVE-2018-1472938Наблюдать
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %comsenz · discuz\!22 мая 2019 г.
- CVE-2018-2042232Наблюдать
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %comsenz · discuzx24 дек. 2018 г.
- CVE-2018-2042332Наблюдать
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-exist
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %comsenz · discuzx24 дек. 2018 г.
- CVE-2008-355430Наблюдать
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %comsenz · discuz8 авг. 2008 г.
- CVE-2009-318530Наблюдать
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQ
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %comsenz · crazy star plugin15 сент. 2009 г.
- CVE-2008-695828Наблюдать
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula p
СредняяCVSS 6,5Proof of conceptEPSS 6 %comsenz · crossday discuz\! board12 авг. 2009 г.
- CVE-2018-2042423Наблюдать
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unb
СредняяCVSS 5,9Эксплойта нетEPSS 1 %comsenz · discuzx24 дек. 2018 г.