Записи HelpDezk
7 опубликованных записей вендора helpdezk.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-285 Improper Authorization1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-8337Эксплойта нет | Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackhelpdezk · helpdezk · CWE-434 | Критическая9,8 | — | 4,8 % | 3 янв. 2020 г. |
39Наблюдать | CVE-2017-14145Эксплойта нет | HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, relahelpdezk · helpdezk · CWE-89 | Критическая9,8 | — | 1,2 % | 5 сент. 2017 г. |
36Наблюдать | CVE-2017-7447Proof of concept | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.helpdezk · helpdezk · CWE-352 | Высокая8,8 | — | 3,5 % | 5 апр. 2017 г. |
36Наблюдать | CVE-2017-7446Proof of concept | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.helpdezk · helpdezk · CWE-352 | Высокая8,8 | — | 3,1 % | 5 апр. 2017 г. |
35Наблюдать | CVE-2017-14146Эксплойта нет | HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk · helpdezk · CWE-94 | Высокая8,8 | — | 1,3 % | 5 сент. 2017 г. |
34Наблюдать | CVE-2023-3037Эксплойта нет | HelpDezk Community improper authorizationhelpdezk · helpdezk · CWE-285 | Высокая8,6 | — | 0,6 % | 4 окт. 2023 г. |
30Наблюдать | CVE-2023-3038Эксплойта нет | HelpDezk Community improper authorizationhelpdezk · helpdezk · CWE-89 | Высокая7,5 | — | 0,6 % | 4 окт. 2023 г. |
- CVE-2014-833740В плане
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attack
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %helpdezk · helpdezk3 янв. 2020 г.
- CVE-2017-1414539Наблюдать
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, rela
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %helpdezk · helpdezk5 сент. 2017 г.
- CVE-2017-744736Наблюдать
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %helpdezk · helpdezk5 апр. 2017 г.
- CVE-2017-744636Наблюдать
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %helpdezk · helpdezk5 апр. 2017 г.
- CVE-2017-1414635Наблюдать
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %helpdezk · helpdezk5 сент. 2017 г.
- CVE-2023-303734Наблюдать
HelpDezk Community improper authorization
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %helpdezk · helpdezk4 окт. 2023 г.
- CVE-2023-303830Наблюдать
HelpDezk Community improper authorization
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %helpdezk · helpdezk4 окт. 2023 г.