Перейти к содержимому
Noroxi

Записи Mfscripts

14 опубликованных записей вендора mfscripts.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

14 записей
  • CVE-2019-20062
    39Наблюдать

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mfscripts · yetishare10 февр. 2020 г.

  • CVE-2019-19735
    36Наблюдать

    class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19734
    35Наблюдать

    _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-20059
    35Наблюдать

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    mfscripts · yetishare10 февр. 2020 г.

  • CVE-2019-19737
    35Наблюдать

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-20060
    30Наблюдать

    MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mfscripts · yetishare10 февр. 2020 г.

  • CVE-2019-20061
    30Наблюдать

    The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mfscripts · yetishare10 февр. 2020 г.

  • CVE-2019-19739
    30Наблюдать

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19732
    28Наблюдать

    translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19738
    24Наблюдать

    log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19733
    24Наблюдать

    _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19736
    24Наблюдать

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19805
    21Наблюдать

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2019-19806
    21Наблюдать

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.