Записи gplhost
16 опубликованных записей вендора gplhost.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 56,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-255 Credentials Management Errors1
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2011-5274Эксплойта нет | The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remogplhost · domain technologie control | Высокая7,5 | — | 2,0 % | 21 мар. 2014 г. |
30Наблюдать | CVE-2011-0434Эксплойта нет | Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL comgplhost · domain technologie control · CWE-89 | Высокая7,5 | — | 1,6 % | 7 мар. 2011 г. |
30Наблюдать | CVE-2009-0402Эксплойта нет | SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute gplhost · domain technologie control · CWE-89 | Высокая7,5 | — | 1,4 % | 3 февр. 2009 г. |
30Наблюдать | CVE-2011-5275Эксплойта нет | The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it eagplhost · domain technologie control · CWE-264 | Высокая7,5 | — | 1,3 % | 21 мар. 2014 г. |
27Наблюдать | CVE-2008-4951Эксплойта нет | dtc 0.29.6 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/awstats.log, (b) /tmp/spam.log.#####, and (c) /tgplhost · dtc-common · CWE-59 | Средняя6,9 | — | 0,4 % | 5 нояб. 2008 г. |
26Наблюдать | CVE-2011-3195Эксплойта нет | shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands vgplhost · domain technologie control · CWE-20 | Средняя6,5 | — | 1,6 % | 21 мар. 2014 г. |
26Наблюдать | CVE-2011-5273Эксплойта нет | Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated gplhost · domain technologie control · CWE-22 | Средняя6,5 | — | 1,5 % | 21 мар. 2014 г. |
26Наблюдать | CVE-2011-3197Эксплойта нет | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL comgplhost · domain technologie control · CWE-89 | Средняя6,5 | — | 1,2 % | 21 мар. 2014 г. |
26Наблюдать | CVE-2011-5276Эксплойта нет | SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (gplhost · domain technologie control · CWE-89 | Средняя6,5 | — | 1,1 % | 21 мар. 2014 г. |
26Наблюдать | CVE-2011-5272Эксплойта нет | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL comgplhost · domain technologie control · CWE-89 | Средняя6,5 | — | 1,1 % | 21 мар. 2014 г. |
21Наблюдать | CVE-2011-0435Эксплойта нет | Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.phgplhost · domain technologie control · CWE-287 | Средняя5,0 | — | 2,0 % | 7 мар. 2011 г. |
21Наблюдать | CVE-2011-0436Эксплойта нет | The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password ingplhost · domain technologie control · CWE-310 | Средняя5,0 | — | 1,9 % | 7 мар. 2011 г. |
16Наблюдать | CVE-2011-0437Эксплойта нет | shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authentgplhost · domain technologie control · CWE-264 | Средняя4,0 | — | 1,6 % | 7 мар. 2011 г. |
14Наблюдать | CVE-2011-3199Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authenticated users to ingplhost · domain technologie control · CWE-79 | Низкая3,5 | — | 1,0 % | 21 мар. 2014 г. |
8Наблюдать | CVE-2011-3196Эксплойта нет | The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allogplhost · domain technologie control · CWE-264 | Низкая2,1 | — | 0,3 % | 21 мар. 2014 г. |
8Наблюдать | CVE-2011-3198Эксплойта нет | Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local usergplhost · domain technologie control · CWE-255 | Низкая2,1 | — | 0,3 % | 21 мар. 2014 г. |
- CVE-2011-527431Наблюдать
The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remo
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-043430Наблюдать
Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL com
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gplhost · domain technologie control7 мар. 2011 г.
- CVE-2009-040230Наблюдать
SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gplhost · domain technologie control3 февр. 2009 г.
- CVE-2011-527530Наблюдать
The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it ea
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2008-495127Наблюдать
dtc 0.29.6 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/awstats.log, (b) /tmp/spam.log.#####, and (c) /t
СредняяCVSS 6,9Эксплойта нетEPSS 0 %gplhost · dtc-common5 нояб. 2008 г.
- CVE-2011-319526Наблюдать
shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands v
СредняяCVSS 6,5Эксплойта нетEPSS 2 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-527326Наблюдать
Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-319726Наблюдать
SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL com
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-527626Наблюдать
SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-527226Наблюдать
SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL com
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-043521Наблюдать
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.ph
СредняяCVSS 5,0Эксплойта нетEPSS 2 %gplhost · domain technologie control7 мар. 2011 г.
- CVE-2011-043621Наблюдать
The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in
СредняяCVSS 5,0Эксплойта нетEPSS 2 %gplhost · domain technologie control7 мар. 2011 г.
- CVE-2011-043716Наблюдать
shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authent
СредняяCVSS 4,0Эксплойта нетEPSS 2 %gplhost · domain technologie control7 мар. 2011 г.
- CVE-2011-319914Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authenticated users to in
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-31968Наблюдать
The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allo
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %gplhost · domain technologie control21 мар. 2014 г.
- CVE-2011-31988Наблюдать
Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local user
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %gplhost · domain technologie control21 мар. 2014 г.