Записи phome
17 опубликованных записей вендора phome.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-693 Protection Mechanism Failure1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-18869Эксплойта нет | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/ephome · empirecms · CWE-22 | Критическая9,8 | — | 3,7 % | 31 окт. 2018 г. |
40В плане | CVE-2020-22937Эксплойта нет | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious cphome · empirecms · CWE-94 | Критическая9,8 | — | 2,8 % | 17 авг. 2021 г. |
39Наблюдать | CVE-2018-20300Эксплойта нет | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this phome · empirecms · CWE-94 | Критическая9,8 | — | 1,6 % | 19 дек. 2018 г. |
39Наблюдать | CVE-2022-28585Эксплойта нет | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.phpphome · empirecms · CWE-89 | Критическая9,8 | — | 1,0 % | 3 мая 2022 г. |
35Наблюдать | CVE-2018-18086Эксплойта нет | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.phome · empirecms · CWE-434 | Высокая8,8 | — | 1,5 % | 9 окт. 2018 г. |
35Наблюдать | CVE-2018-18449Эксплойта нет | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16phome · empirecms · CWE-352 | Высокая8,8 | — | 0,7 % | 7 мар. 2019 г. |
35Наблюдать | CVE-2018-16339Эксплойта нет | An issue was discovered in EmpireCMS 7.0.phome · empirecms · CWE-352 | Высокая8,8 | — | 0,5 % | 2 сент. 2018 г. |
29Наблюдать | CVE-2018-19462Эксплойта нет | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filenamphome · empirecms · CWE-89 | Высокая7,2 | — | 2,2 % | 7 июн. 2019 г. |
28Наблюдать | CVE-2012-5777Эксплойта нет | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assiphome · empirecms · CWE-94 | Средняя6,8 | — | 2,2 % | 15 нояб. 2012 г. |
28Наблюдать | CVE-2023-50162Эксплойта нет | SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the Dophome · empirecms · CWE-89 | Высокая7,2 | — | 1,0 % | 8 янв. 2024 г. |
24Наблюдать | CVE-2019-12362Эксплойта нет | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.phome · empirecms · CWE-79 | Средняя6,1 | — | 0,8 % | 27 мая 2019 г. |
24Наблюдать | CVE-2019-12361Эксплойта нет | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page temphome · empirecms · CWE-79 | Средняя6,1 | — | 0,4 % | 27 мая 2019 г. |
22Наблюдать | CVE-2018-6881Эксплойта нет | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.dedecms · dedecms · CWE-200 | Средняя5,3 | — | 2,2 % | 11 февр. 2018 г. |
22Наблюдать | CVE-2018-6880Эксплойта нет | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.phome · empirecms · CWE-668 | Средняя5,3 | — | 1,8 % | 11 февр. 2018 г. |
22Наблюдать | CVE-2025-15422Эксплойта нет | EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanismphome · empirecms · CWE-693 | Средняя5,5 | — | 1,3 % | 1 янв. 2026 г. |
19Наблюдать | CVE-2018-19461Эксплойта нет | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.phome · empirecms · CWE-79 | Средняя4,8 | — | 0,9 % | 7 июн. 2019 г. |
8Наблюдать | CVE-2025-15423Эксплойта нет | EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted uploadphome · empirecms · CWE-284 | Низкая2,1 | — | 0,4 % | 1 янв. 2026 г. |
- CVE-2018-1886940В плане
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %phome · empirecms31 окт. 2018 г.
- CVE-2020-2293740В плане
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious c
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phome · empirecms17 авг. 2021 г.
- CVE-2018-2030039Наблюдать
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phome · empirecms19 дек. 2018 г.
- CVE-2022-2858539Наблюдать
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phome · empirecms3 мая 2022 г.
- CVE-2018-1808635Наблюдать
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phome · empirecms9 окт. 2018 г.
- CVE-2018-1844935Наблюдать
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phome · empirecms7 мар. 2019 г.
- CVE-2018-1633935Наблюдать
An issue was discovered in EmpireCMS 7.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phome · empirecms2 сент. 2018 г.
- CVE-2018-1946229Наблюдать
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filenam
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %phome · empirecms7 июн. 2019 г.
- CVE-2012-577728Наблюдать
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assi
СредняяCVSS 6,8Эксплойта нетEPSS 2 %phome · empirecms15 нояб. 2012 г.
- CVE-2023-5016228Наблюдать
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the Do
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %phome · empirecms8 янв. 2024 г.
- CVE-2019-1236224Наблюдать
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %phome · empirecms27 мая 2019 г.
- CVE-2019-1236124Наблюдать
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page tem
СредняяCVSS 6,1Эксплойта нетEPSS 0 %phome · empirecms27 мая 2019 г.
- CVE-2018-688122Наблюдать
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %dedecms · dedecms11 февр. 2018 г.
- CVE-2018-688022Наблюдать
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %phome · empirecms11 февр. 2018 г.
- CVE-2025-1542222Наблюдать
EmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism
СредняяCVSS 5,5Эксплойта нетEPSS 1 %phome · empirecms1 янв. 2026 г.
- CVE-2018-1946119Наблюдать
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %phome · empirecms7 июн. 2019 г.
- CVE-2025-154238Наблюдать
EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %phome · empirecms1 янв. 2026 г.