Записи Mfscripts
14 опубликованных записей вендора mfscripts.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2019-20062Эксплойта нет | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until umfscripts · yetishare · CWE-287 | Критическая9,8 | — | 1,6 % | 10 февр. 2020 г. |
36Наблюдать | CVE-2019-19735Эксплойта нет | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micromfscripts · yetishare · CWE-916 | Критическая9,1 | — | 0,8 % | 30 дек. 2019 г. |
35Наблюдать | CVE-2019-19734Эксплойта нет | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.mfscripts · yetishare · CWE-89 | Высокая8,8 | — | 1,1 % | 30 дек. 2019 г. |
35Наблюдать | CVE-2019-20059Proof of concept | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 mfscripts · yetishare · CWE-89 | Высокая8,8 | — | 0,9 % | 10 февр. 2020 г. |
35Наблюдать | CVE-2019-19737Эксплойта нет | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requmfscripts · yetishare · CWE-352 | Высокая8,8 | — | 0,5 % | 30 дек. 2019 г. |
30Наблюдать | CVE-2019-20060Эксплойта нет | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.mfscripts · yetishare · CWE-922 | Высокая7,5 | — | 1,4 % | 10 февр. 2020 г. |
30Наблюдать | CVE-2019-20061Эксплойта нет | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleamfscripts · yetishare · CWE-319 | Высокая7,5 | — | 0,9 % | 10 февр. 2020 г. |
30Наблюдать | CVE-2019-19739Эксплойта нет | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channmfscripts · yetishare · CWE-311 | Высокая7,5 | — | 0,7 % | 30 дек. 2019 г. |
28Наблюдать | CVE-2019-19732Эксплойта нет | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSmfscripts · yetishare · CWE-89 | Высокая7,2 | — | 1,1 % | 30 дек. 2019 г. |
24Наблюдать | CVE-2019-19738Эксплойта нет | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, mfscripts · yetishare · CWE-79 | Средняя6,1 | — | 0,7 % | 30 дек. 2019 г. |
24Наблюдать | CVE-2019-19733Эксплойта нет | _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize ormfscripts · yetishare · CWE-79 | Средняя6,1 | — | 0,7 % | 30 дек. 2019 г. |
24Наблюдать | CVE-2019-19736Эксплойта нет | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which cmfscripts · yetishare · CWE-732 | Средняя6,1 | — | 0,6 % | 30 дек. 2019 г. |
21Наблюдать | CVE-2019-19805Эксплойта нет | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whethermfscripts · yetishare · CWE-203 | Средняя5,3 | — | 1,0 % | 30 дек. 2019 г. |
21Наблюдать | CVE-2019-19806Эксплойта нет | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confimfscripts · yetishare · CWE-209 | Средняя5,3 | — | 1,0 % | 30 дек. 2019 г. |
- CVE-2019-2006239Наблюдать
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mfscripts · yetishare10 февр. 2020 г.
- CVE-2019-1973536Наблюдать
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1973435Наблюдать
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-2005935Наблюдать
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %mfscripts · yetishare10 февр. 2020 г.
- CVE-2019-1973735Наблюдать
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-2006030Наблюдать
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mfscripts · yetishare10 февр. 2020 г.
- CVE-2019-2006130Наблюдать
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mfscripts · yetishare10 февр. 2020 г.
- CVE-2019-1973930Наблюдать
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1973228Наблюдать
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1973824Наблюдать
log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1973324Наблюдать
_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1973624Наблюдать
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1980521Наблюдать
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether
СредняяCVSS 5,3Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2019-1980621Наблюдать
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi
СредняяCVSS 5,3Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.