Записи idreamsoft
30 опубликованных записей вендора idreamsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-7160Эксплойта нет | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in executidreamsoft · icms · CWE-22 | Критическая9,8 | — | 3,4 % | 29 янв. 2019 г. |
40В плане | CVE-2021-44978Эксплойта нет | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.idreamsoft · icms · CWE-94 | Критическая9,8 | — | 2,2 % | 4 февр. 2022 г. |
39Наблюдать | CVE-2020-19142Эксплойта нет | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.idreamsoft · icms · CWE-78 | Критическая9,8 | — | 1,6 % | 10 дек. 2020 г. |
39Наблюдать | CVE-2020-19527Эксплойта нет | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.idreamsoft · icms · CWE-78 | Критическая9,8 | — | 1,6 % | 10 дек. 2020 г. |
39Наблюдать | CVE-2019-17552Эксплойта нет | An issue was discovered in idreamsoft iCMS v7.0.14.idreamsoft · icms · CWE-89 | Критическая9,8 | — | 1,1 % | 14 окт. 2019 г. |
39Наблюдать | CVE-2022-41496Эксплойта нет | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.idreamsoft · icms · CWE-918 | Критическая9,8 | — | 1,0 % | 13 окт. 2022 г. |
39Наблюдать | CVE-2023-39806Эксплойта нет | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.idreamsoft · icms · CWE-89 | Критическая9,8 | — | 0,6 % | 10 авг. 2023 г. |
39Наблюдать | CVE-2023-39805Эксплойта нет | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.idreamsoft · icms · CWE-89 | Критическая9,8 | — | 0,6 % | 10 авг. 2023 г. |
37Наблюдать | CVE-2019-7234Эксплойта нет | An issue was discovered in idreamsoft iCMS 7.0.13.idreamsoft · icms · CWE-22 | Критическая9,1 | — | 2,2 % | 30 янв. 2019 г. |
37Наблюдать | CVE-2020-18070Эксплойта нет | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()"idreamsoft · icms · CWE-22 | Критическая9,1 | — | 2,2 % | 29 апр. 2021 г. |
35Наблюдать | CVE-2018-16366Эксплойта нет | An issue was discovered in idreamsoft iCMS V7.0.10.idreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,6 % | 2 сент. 2018 г. |
35Наблюдать | CVE-2018-16332Эксплойта нет | An issue was discovered in iCMS 7.0.9.idreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,6 % | 1 сент. 2018 г. |
35Наблюдать | CVE-2018-16365Эксплойта нет | An issue was discovered in idreamsoft iCMS V7.0.10.idreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,6 % | 2 сент. 2018 г. |
35Наблюдать | CVE-2020-21141Эксплойта нет | iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.idreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,6 % | 12 нояб. 2021 г. |
35Наблюдать | CVE-2020-26641Эксплойта нет | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scriptsidreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,5 % | 28 мая 2021 г. |
35Наблюдать | CVE-2023-40953Эксплойта нет | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).idreamsoft · icms · CWE-352 | Высокая8,8 | — | 0,3 % | 7 сент. 2023 г. |
31Наблюдать | CVE-2019-7235Эксплойта нет | An issue was discovered in idreamsoft iCMS 7.0.13.idreamsoft · icms · CWE-22 | Высокая7,5 | — | 2,5 % | 30 янв. 2019 г. |
31Наблюдать | CVE-2019-7237Эксплойта нет | An issue was discovered in idreamsoft iCMS 7.0.13 on Windows.idreamsoft · icms · CWE-22 | Высокая7,5 | — | 2,2 % | 30 янв. 2019 г. |
31Наблюдать | CVE-2019-7236Эксплойта нет | An issue was discovered in idreamsoft iCMS 7.0.13.idreamsoft · icms · CWE-22 | Высокая7,5 | — | 2,2 % | 30 янв. 2019 г. |
30Наблюдать | CVE-2021-44977Эксплойта нет | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.idreamsoft · icms · CWE-22 | Высокая7,5 | — | 1,6 % | 4 февр. 2022 г. |
30Наблюдать | CVE-2019-17583Эксплойта нет | idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstidreamsoft · icms · CWE-770 | Высокая7,5 | — | 1,3 % | 14 окт. 2019 г. |
29Наблюдать | CVE-2018-16320Эксплойта нет | idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.idreamsoft · icms · CWE-22 | Высокая7,2 | — | 2,4 % | 1 сент. 2018 г. |
26Наблюдать | CVE-2019-16677Эксплойта нет | An issue was discovered in idreamsoft iCMS V7.0.idreamsoft · icms · CWE-352 | Средняя6,5 | — | 0,5 % | 21 сент. 2019 г. |
26Наблюдать | CVE-2020-24739Эксплойта нет | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account.idreamsoft · icms · CWE-352 | Средняя6,5 | — | 0,4 % | 10 сент. 2020 г. |
24Наблюдать | CVE-2018-13865Эксплойта нет | An issue was discovered in idreamsoft iCMS 7.0.9.idreamsoft · icms · CWE-79 | Средняя6,1 | — | 1,0 % | 10 июл. 2018 г. |
- CVE-2019-716040В плане
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execut
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %idreamsoft · icms29 янв. 2019 г.
- CVE-2021-4497840В плане
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %idreamsoft · icms4 февр. 2022 г.
- CVE-2020-1914239Наблюдать
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %idreamsoft · icms10 дек. 2020 г.
- CVE-2020-1952739Наблюдать
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %idreamsoft · icms10 дек. 2020 г.
- CVE-2019-1755239Наблюдать
An issue was discovered in idreamsoft iCMS v7.0.14.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %idreamsoft · icms14 окт. 2019 г.
- CVE-2022-4149639Наблюдать
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %idreamsoft · icms13 окт. 2022 г.
- CVE-2023-3980639Наблюдать
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %idreamsoft · icms10 авг. 2023 г.
- CVE-2023-3980539Наблюдать
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %idreamsoft · icms10 авг. 2023 г.
- CVE-2019-723437Наблюдать
An issue was discovered in idreamsoft iCMS 7.0.13.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %idreamsoft · icms30 янв. 2019 г.
- CVE-2020-1807037Наблюдать
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()"
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %idreamsoft · icms29 апр. 2021 г.
- CVE-2018-1636635Наблюдать
An issue was discovered in idreamsoft iCMS V7.0.10.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %idreamsoft · icms2 сент. 2018 г.
- CVE-2018-1633235Наблюдать
An issue was discovered in iCMS 7.0.9.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %idreamsoft · icms1 сент. 2018 г.
- CVE-2018-1636535Наблюдать
An issue was discovered in idreamsoft iCMS V7.0.10.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %idreamsoft · icms2 сент. 2018 г.
- CVE-2020-2114135Наблюдать
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %idreamsoft · icms12 нояб. 2021 г.
- CVE-2020-2664135Наблюдать
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %idreamsoft · icms28 мая 2021 г.
- CVE-2023-4095335Наблюдать
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %idreamsoft · icms7 сент. 2023 г.
- CVE-2019-723531Наблюдать
An issue was discovered in idreamsoft iCMS 7.0.13.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %idreamsoft · icms30 янв. 2019 г.
- CVE-2019-723731Наблюдать
An issue was discovered in idreamsoft iCMS 7.0.13 on Windows.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %idreamsoft · icms30 янв. 2019 г.
- CVE-2019-723631Наблюдать
An issue was discovered in idreamsoft iCMS 7.0.13.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %idreamsoft · icms30 янв. 2019 г.
- CVE-2021-4497730Наблюдать
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %idreamsoft · icms4 февр. 2022 г.
- CVE-2019-1758330Наблюдать
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonst
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %idreamsoft · icms14 окт. 2019 г.
- CVE-2018-1632029Наблюдать
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %idreamsoft · icms1 сент. 2018 г.
- CVE-2019-1667726Наблюдать
An issue was discovered in idreamsoft iCMS V7.0.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %idreamsoft · icms21 сент. 2019 г.
- CVE-2020-2473926Наблюдать
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %idreamsoft · icms10 сент. 2020 г.
- CVE-2018-1386524Наблюдать
An issue was discovered in idreamsoft iCMS 7.0.9.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %idreamsoft · icms10 июл. 2018 г.