Записи dynpg
11 опубликованных записей вендора dynpg.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2010-4400Proof of concept | SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_Udynpg · dynpg · CWE-89 | Высокая7,5 | — | 2,2 % | 6 дек. 2010 г. |
23Наблюдать | CVE-2010-1299Proof of concept | Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_dynpg · dynpg · CWE-94 | Средняя5,1 | — | 10,7 % | 7 апр. 2010 г. |
22Наблюдать | CVE-2010-4401Proof of concept | languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installdynpg · dynpg · CWE-200 | Средняя5,0 | — | 5,6 % | 6 дек. 2010 г. |
21Наблюдать | CVE-2020-27406Эксплойта нет | Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.dynpg · dynpg · CWE-79 | Средняя5,4 | — | 0,8 % | 2 нояб. 2021 г. |
19Наблюдать | CVE-2010-4399Proof of concept | Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackdynpg · dynpg · CWE-22 | Средняя4,3 | — | 5,6 % | 6 дек. 2010 г. |
19Наблюдать | CVE-2021-27531Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
19Наблюдать | CVE-2021-27527Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
19Наблюдать | CVE-2021-27528Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
19Наблюдать | CVE-2021-27529Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
19Наблюдать | CVE-2021-27530Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
19Наблюдать | CVE-2021-27526Эксплойта нет | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.dynpg · dynpg · CWE-79 | Средняя4,8 | — | 0,8 % | 23 мар. 2021 г. |
- CVE-2010-440031Наблюдать
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_U
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %dynpg · dynpg6 дек. 2010 г.
- CVE-2010-129923Наблюдать
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_
СредняяCVSS 5,1Proof of conceptEPSS 11 %dynpg · dynpg7 апр. 2010 г.
- CVE-2010-440122Наблюдать
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the install
СредняяCVSS 5,0Proof of conceptEPSS 6 %dynpg · dynpg6 дек. 2010 г.
- CVE-2020-2740621Наблюдать
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dynpg · dynpg2 нояб. 2021 г.
- CVE-2010-439919Наблюдать
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attack
СредняяCVSS 4,3Proof of conceptEPSS 6 %dynpg · dynpg6 дек. 2010 г.
- CVE-2021-2753119Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.
- CVE-2021-2752719Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.
- CVE-2021-2752819Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.
- CVE-2021-2752919Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.
- CVE-2021-2753019Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.
- CVE-2021-2752619Наблюдать
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %dynpg · dynpg23 мар. 2021 г.