Записи creatiwity
7 опубликованных записей вендора creatiwity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-12065Эксплойта нет | A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP fcreatiwity · witycms · CWE-20 | Критическая9,8 | — | 2,6 % | 8 июн. 2018 г. |
36Наблюдать | CVE-2018-14029Proof of concept | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifyicreatiwity · witycms · CWE-352 | Высокая8,8 | — | 2,5 % | 12 июл. 2018 г. |
35Наблюдать | CVE-2022-29725Эксплойта нет | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.creatiwity · witycms · CWE-434 | Высокая8,8 | — | 1,4 % | 2 июн. 2022 г. |
21Наблюдать | CVE-2018-16250Эксплойта нет | The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first nacreatiwity · witycms · CWE-79 | Средняя5,4 | — | 0,6 % | 20 июн. 2019 г. |
20Наблюдать | CVE-2018-11512Proof of concept | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatcreatiwity · witycms · CWE-79 | Средняя4,8 | — | 2,2 % | 28 мая 2018 г. |
19Наблюдать | CVE-2018-16776Эксплойта нет | wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.creatiwity · witycms · CWE-79 | Средняя4,8 | — | 0,7 % | 10 сент. 2018 г. |
17Наблюдать | CVE-2018-16251Эксплойта нет | A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu.creatiwity · witycms · CWE-89 | Средняя4,3 | — | 0,9 % | 20 июн. 2019 г. |
- CVE-2018-1206540В плане
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP f
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %creatiwity · witycms8 июн. 2018 г.
- CVE-2018-1402936Наблюдать
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifyi
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %creatiwity · witycms12 июл. 2018 г.
- CVE-2022-2972535Наблюдать
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %creatiwity · witycms2 июн. 2022 г.
- CVE-2018-1625021Наблюдать
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first na
СредняяCVSS 5,4Эксплойта нетEPSS 1 %creatiwity · witycms20 июн. 2019 г.
- CVE-2018-1151220Наблюдать
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creat
СредняяCVSS 4,8Proof of conceptEPSS 2 %creatiwity · witycms28 мая 2018 г.
- CVE-2018-1677619Наблюдать
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %creatiwity · witycms10 сент. 2018 г.
- CVE-2018-1625117Наблюдать
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %creatiwity · witycms20 июн. 2019 г.