Записи maarch
8 опубликованных записей вендора maarch.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 12,5 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2015-1587Готовый эксплойт | Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote atmaarch · gec\/ged | Высокая7,5 | — | 44,2 % | 19 февр. 2015 г. |
36Наблюдать | CVE-2019-15855Эксплойта нет | An issue was discovered in Maarch RM before 2.5.maarch · maarch rm · CWE-22 | Критическая9,1 | — | 1,5 % | 17 янв. 2020 г. |
35Наблюдать | CVE-2019-15854Эксплойта нет | An issue was discovered in Maarch RM before 2.5.maarch · maarch rm | Высокая8,8 | — | 1,3 % | 17 янв. 2020 г. |
30Наблюдать | CVE-2022-37772Эксплойта нет | Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the amaarch · maarch rm · CWE-307 | Высокая7,5 | — | 1,2 % | 22 нояб. 2022 г. |
26Наблюдать | CVE-2022-37773Эксплойта нет | An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allowmaarch · maarch rm · CWE-89 | Средняя6,5 | — | 0,8 % | 22 нояб. 2022 г. |
21Наблюдать | CVE-2014-8995Proof of concept | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.maarch · letterbox · CWE-89 | Средняя5,0 | — | 2,2 % | 20 нояб. 2014 г. |
21Наблюдать | CVE-2022-37774Эксплойта нет | There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.maarch · maarch rm · CWE-287 | Средняя5,3 | — | 0,6 % | 22 нояб. 2022 г. |
16Наблюдать | CVE-2006-5492Эксплойта нет | Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (documenmaarch · maarch | Средняя4,0 | — | 1,2 % | 25 окт. 2006 г. |
- CVE-2015-158743В плане
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote at
ВысокаяCVSS 7,5Готовый эксплойтEPSS 44 %maarch · gec\/ged19 февр. 2015 г.
- CVE-2019-1585536Наблюдать
An issue was discovered in Maarch RM before 2.5.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %maarch · maarch rm17 янв. 2020 г.
- CVE-2019-1585435Наблюдать
An issue was discovered in Maarch RM before 2.5.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %maarch · maarch rm17 янв. 2020 г.
- CVE-2022-3777230Наблюдать
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %maarch · maarch rm22 нояб. 2022 г.
- CVE-2022-3777326Наблюдать
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allow
СредняяCVSS 6,5Эксплойта нетEPSS 1 %maarch · maarch rm22 нояб. 2022 г.
- CVE-2014-899521Наблюдать
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
СредняяCVSS 5,0Proof of conceptEPSS 2 %maarch · letterbox20 нояб. 2014 г.
- CVE-2022-3777421Наблюдать
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %maarch · maarch rm22 нояб. 2022 г.
- CVE-2006-549216Наблюдать
Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (documen
СредняяCVSS 4,0Эксплойта нетEPSS 1 %maarch · maarch25 окт. 2006 г.