Записи onefilecms
6 опубликованных записей вендора onefilecms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2018-13123Эксплойта нет | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated byonefilecms · onefilecms · CWE-200 | Критическая9,8 | — | 1,4 % | 3 июл. 2018 г. |
39Наблюдать | CVE-2018-12993Эксплойта нет | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefileonefilecms · onefilecms · CWE-307 | Критическая9,8 | — | 1,2 % | 29 июн. 2018 г. |
35Наблюдать | CVE-2018-12994Эксплойта нет | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screonefilecms · onefilecms · CWE-94 | Высокая8,8 | — | 1,2 % | 29 июн. 2018 г. |
35Наблюдать | CVE-2018-12995Эксплойта нет | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screenonefilecms · onefilecms · CWE-94 | Высокая8,8 | — | 1,2 % | 29 июн. 2018 г. |
26Наблюдать | CVE-2018-13122Эксплойта нет | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstratonefilecms · onefilecms · CWE-732 | Средняя6,5 | — | 0,8 % | 3 июл. 2018 г. |
19Наблюдать | CVE-2019-8408Эксплойта нет | OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.onefilecms · onefilecms | Средняя4,9 | — | 1,2 % | 17 февр. 2019 г. |
- CVE-2018-1312339Наблюдать
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %onefilecms · onefilecms3 июл. 2018 г.
- CVE-2018-1299339Наблюдать
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefile
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %onefilecms · onefilecms29 июн. 2018 г.
- CVE-2018-1299435Наблюдать
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File scre
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %onefilecms · onefilecms29 июн. 2018 г.
- CVE-2018-1299535Наблюдать
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %onefilecms · onefilecms29 июн. 2018 г.
- CVE-2018-1312226Наблюдать
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrat
СредняяCVSS 6,5Эксплойта нетEPSS 1 %onefilecms · onefilecms3 июл. 2018 г.
- CVE-2019-840819Наблюдать
OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %onefilecms · onefilecms17 февр. 2019 г.