Перейти к содержимому
Noroxi

Записи eprints

6 опубликованных записей вендора eprints.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 21

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

6 записей
  • CVE-2021-3342
    40В плане

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    eprints · eprints1 мар. 2021 г.

  • CVE-2021-26703
    40В плане

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    eprints · eprints1 мар. 2021 г.

  • CVE-2021-26476
    40В плане

    EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    eprints · eprints1 мар. 2021 г.

  • CVE-2021-26704
    36Наблюдать

    EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    eprints · eprints1 мар. 2021 г.

  • CVE-2021-26475
    26Наблюдать

    EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

    СредняяCVSS 6,1Proof of conceptEPSS 7 %

    eprints · eprints1 мар. 2021 г.

  • CVE-2021-26702
    25Наблюдать

    EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    eprints · eprints1 мар. 2021 г.