Записи eprints
6 опубликованных записей вендора eprints.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-3342Эксплойта нет | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latexeprints · eprints · CWE-78 | Критическая9,8 | — | 4,2 % | 1 мар. 2021 г. |
40В плане | CVE-2021-26703Эксплойта нет | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase eprints · eprints · CWE-611 | Критическая9,8 | — | 4,0 % | 1 мар. 2021 г. |
40В плане | CVE-2021-26476Эксплойта нет | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.eprints · eprints · CWE-78 | Критическая9,8 | — | 3,1 % | 1 мар. 2021 г. |
36Наблюдать | CVE-2021-26704Эксплойта нет | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.eprints · eprints · CWE-78 | Высокая8,8 | — | 3,1 % | 1 мар. 2021 г. |
26Наблюдать | CVE-2021-26475Proof of concept | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.eprints · eprints · CWE-79 | Средняя6,1 | — | 7,3 % | 1 мар. 2021 г. |
25Наблюдать | CVE-2021-26702Proof of concept | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.eprints · eprints · CWE-79 | Средняя6,1 | — | 3,1 % | 1 мар. 2021 г. |
- CVE-2021-334240В плане
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %eprints · eprints1 мар. 2021 г.
- CVE-2021-2670340В плане
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %eprints · eprints1 мар. 2021 г.
- CVE-2021-2647640В плане
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %eprints · eprints1 мар. 2021 г.
- CVE-2021-2670436Наблюдать
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %eprints · eprints1 мар. 2021 г.
- CVE-2021-2647526Наблюдать
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
СредняяCVSS 6,1Proof of conceptEPSS 7 %eprints · eprints1 мар. 2021 г.
- CVE-2021-2670225Наблюдать
EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
СредняяCVSS 6,1Proof of conceptEPSS 3 %eprints · eprints1 мар. 2021 г.