Записи ens
7 опубликованных записей вендора ens.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2018-19510Эксплойта нет | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.ens · webgalamb · CWE-89 | Критическая9,8 | — | 20,0 % | 21 мар. 2019 г. |
40В плане | CVE-2018-19514Эксплойта нет | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.ens · webgalamb · CWE-434 | Критическая9,8 | — | 4,9 % | 21 мар. 2019 г. |
40В плане | CVE-2018-19515Эксплойта нет | In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.ens · webgalamb · CWE-863 | Критическая9,8 | — | 2,9 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2018-19513Эксплойта нет | In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenens · webgalamb · CWE-532 | Высокая7,5 | — | 2,1 % | 21 мар. 2019 г. |
30Наблюдать | CVE-2018-19512Эксплойта нет | In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by auens · webgalamb · CWE-22 | Высокая7,2 | — | 7,2 % | 21 мар. 2019 г. |
26Наблюдать | CVE-2018-19511Эксплойта нет | wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator pens · webgalamb · CWE-352 | Средняя6,5 | — | 0,7 % | 21 мар. 2019 г. |
24Наблюдать | CVE-2018-19509Эксплойта нет | wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodinens · webgalamb · CWE-79 | Средняя6,1 | — | 1,1 % | 21 мар. 2019 г. |
- CVE-2018-1951045В плане
subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1951440В плане
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1951540В плане
In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1951331Наблюдать
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filen
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1951230Наблюдать
In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by au
ВысокаяCVSS 7,2Эксплойта нетEPSS 7 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1951126Наблюдать
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator p
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ens · webgalamb21 мар. 2019 г.
- CVE-2018-1950924Наблюдать
wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encodin
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ens · webgalamb21 мар. 2019 г.