Записи iwcnetwork
8 опубликованных записей вендора iwcnetwork.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-275 Permission Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-17992Эксплойта нет | Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name iwcnetwork · biometric shift employee management system · CWE-22 | Критическая9,8 | — | 1,8 % | 30 дек. 2017 г. |
35Наблюдать | CVE-2017-17990Эксплойта нет | Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.iwcnetwork · biometric shift employee management system · CWE-352 | Высокая8,8 | — | 0,5 % | 30 дек. 2017 г. |
33Наблюдать | CVE-2017-17876Proof of concept | Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download requestiwcnetwork · shift · CWE-275 | Высокая7,5 | — | 9,5 % | 27 дек. 2017 г. |
21Наблюдать | CVE-2017-17991Эксплойта нет | Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.iwcnetwork · biometric shift employee management system · CWE-79 | Средняя5,4 | — | 0,5 % | 30 дек. 2017 г. |
21Наблюдать | CVE-2017-17989Эксплойта нет | Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.iwcnetwork · biometric shift employee management system · CWE-79 | Средняя5,4 | — | 0,5 % | 30 дек. 2017 г. |
21Наблюдать | CVE-2017-17993Эксплойта нет | Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.iwcnetwork · biometric shift employee management system · CWE-79 | Средняя5,4 | — | 0,5 % | 30 дек. 2017 г. |
21Наблюдать | CVE-2017-17994Эксплойта нет | Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.iwcnetwork · biometric shift employee management system · CWE-79 | Средняя5,4 | — | 0,5 % | 30 дек. 2017 г. |
21Наблюдать | CVE-2017-17995Эксплойта нет | Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.iwcnetwork · biometric shift employee management system · CWE-79 | Средняя5,4 | — | 0,5 % | 30 дек. 2017 г. |
- CVE-2017-1799240В плане
Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1799035Наблюдать
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1787633Наблюдать
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %iwcnetwork · shift27 дек. 2017 г.
- CVE-2017-1799121Наблюдать
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1798921Наблюдать
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1799321Наблюдать
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1799421Наблюдать
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.
- CVE-2017-1799521Наблюдать
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %iwcnetwork · biometric shift employee management system30 дек. 2017 г.