Записи discuz
13 опубликованных записей вендора discuz.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-5377Эксплойта нет | Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.discuz · discuzx · CWE-862 | Критическая9,8 | — | 2,1 % | 12 янв. 2018 г. |
36Наблюдать | CVE-2018-5259Эксплойта нет | Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.discuz · discuzx | Высокая8,8 | — | 2,0 % | 8 янв. 2018 г. |
31Наблюдать | CVE-2008-6957Proof of concept | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasdiscuz · discuz\! · CWE-264 | Высокая7,5 | — | 2,8 % | 12 авг. 2009 г. |
30Наблюдать | CVE-2006-5561Proof of concept | SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cdiscuz · discuz gbk | Высокая7,5 | — | 1,1 % | 27 окт. 2006 г. |
30Наблюдать | CVE-2009-4621Proof of concept | SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands discuz · discuz\! · CWE-89 | Высокая7,5 | — | 1,0 % | 18 янв. 2010 г. |
30Наблюдать | CVE-2010-4912Proof of concept | SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parametdiscuz · ucenter home · CWE-89 | Высокая7,5 | — | 1,0 % | 8 окт. 2011 г. |
28Наблюдать | CVE-2024-30884Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and odiscuz · discuzx · CWE-79 | Высокая7,1 | — | 0,5 % | 11 апр. 2024 г. |
24Наблюдать | CVE-2018-5376Эксплойта нет | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.discuz · discuzx · CWE-79 | Средняя6,1 | — | 0,8 % | 12 янв. 2018 г. |
24Наблюдать | CVE-2018-5375Эксплойта нет | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.discuz · discuzx · CWE-79 | Средняя6,1 | — | 0,8 % | 12 янв. 2018 г. |
24Наблюдать | CVE-2022-45543Эксплойта нет | Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or usernamdiscuz · discuzx · CWE-79 | Средняя6,1 | — | 0,5 % | 15 февр. 2023 г. |
21Наблюдать | CVE-2018-5331Эксплойта нет | Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.discuz · discuzx · CWE-79 | Средняя5,4 | — | 0,6 % | 10 янв. 2018 г. |
21Наблюдать | CVE-2018-10297Эксплойта нет | Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associatediscuz · discuzx · CWE-79 | Средняя5,4 | — | 0,5 % | 22 апр. 2018 г. |
21Наблюдать | CVE-2018-10298Эксплойта нет | Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does discuz · discuzx · CWE-79 | Средняя5,4 | — | 0,5 % | 22 апр. 2018 г. |
- CVE-2018-537740В плане
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %discuz · discuzx12 янв. 2018 г.
- CVE-2018-525936Наблюдать
Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %discuz · discuzx8 янв. 2018 г.
- CVE-2008-695731Наблюдать
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpas
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %discuz · discuz\!12 авг. 2009 г.
- CVE-2006-556130Наблюдать
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth c
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %discuz · discuz gbk27 окт. 2006 г.
- CVE-2009-462130Наблюдать
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %discuz · discuz\!18 янв. 2010 г.
- CVE-2010-491230Наблюдать
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %discuz · ucenter home8 окт. 2011 г.
- CVE-2024-3088428Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and o
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %discuz · discuzx11 апр. 2024 г.
- CVE-2018-537624Наблюдать
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %discuz · discuzx12 янв. 2018 г.
- CVE-2018-537524Наблюдать
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %discuz · discuzx12 янв. 2018 г.
- CVE-2022-4554324Наблюдать
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or usernam
СредняяCVSS 6,1Эксплойта нетEPSS 1 %discuz · discuzx15 февр. 2023 г.
- CVE-2018-533121Наблюдать
Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %discuz · discuzx10 янв. 2018 г.
- CVE-2018-1029721Наблюдать
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associate
СредняяCVSS 5,4Эксплойта нетEPSS 1 %discuz · discuzx22 апр. 2018 г.
- CVE-2018-1029821Наблюдать
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does
СредняяCVSS 5,4Эксплойта нетEPSS 1 %discuz · discuzx22 апр. 2018 г.