Записи pearson
5 опубликованных записей вендора pearson.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-255 Credentials Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2020-36154Эксплойта нет | The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" dpearson · vue testing system · CWE-732 | Высокая7,8 | — | 0,4 % | 4 янв. 2021 г. |
30Наблюдать | CVE-2014-1455Эксплойта нет | SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 andpearson · esis enterprise student information system · CWE-89 | Высокая7,5 | — | 1,3 % | 10 апр. 2014 г. |
20Наблюдать | CVE-2015-0972Эксплойта нет | Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackpearson · proctorcache · CWE-255 | Средняя5,0 | — | 1,4 % | 23 июн. 2015 г. |
19Наблюдать | CVE-2014-1454Эксплойта нет | Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inputpearson · esis enterprise student information system · CWE-79 | Средняя4,8 | — | 0,6 % | 8 янв. 2020 г. |
17Наблюдать | CVE-2014-1942Эксплойта нет | Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote apearson · esis enterprise student information system · CWE-79 | Средняя4,3 | — | 1,0 % | 1 апр. 2014 г. |
- CVE-2020-3615431Наблюдать
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" d
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %pearson · vue testing system4 янв. 2021 г.
- CVE-2014-145530Наблюдать
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pearson · esis enterprise student information system10 апр. 2014 г.
- CVE-2015-097220Наблюдать
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attack
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pearson · proctorcache23 июн. 2015 г.
- CVE-2014-145419Наблюдать
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
СредняяCVSS 4,8Эксплойта нетEPSS 1 %pearson · esis enterprise student information system8 янв. 2020 г.
- CVE-2014-194217Наблюдать
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %pearson · esis enterprise student information system1 апр. 2014 г.