Записи playsms
14 опубликованных записей вендора playsms.
Профиль для исследователя
- Попали в KEV
- 1 · 7,1 %
- С эксплойтом
- 3 · 21,4 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 637 дн.
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-697 Incorrect Comparison1
- CWE-384 Session Fixation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2020-8644Готовый эксплойт | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.playsms · playsms · CWE-94 | Критическая9,8 | KEV | 86,7 % | 5 февр. 2020 г. |
62На этой неделе | CVE-2017-9101Готовый эксплойт | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header aplaysms · playsms · CWE-434 | Критическая9,8 | — | 76,7 % | 21 мая 2017 г. |
54В плане | CVE-2017-9080Готовый эксплойт | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.playsms · playsms · CWE-434 | Высокая8,8 | — | 62,3 % | 19 мая 2017 г. |
40В плане | CVE-2021-40373Proof of concept | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executplaysms · playsms · CWE-94 | Критическая9,8 | — | 4,7 % | 10 сент. 2021 г. |
39Наблюдать | CVE-2022-47034Эксплойта нет | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Критическая9,8 | — | 0,8 % | 13 февр. 2023 г. |
33Наблюдать | CVE-2009-0103Proof of concept | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1playsms · playsms · CWE-94 | Высокая7,5 | — | 10,1 % | 9 янв. 2009 г. |
32Наблюдать | CVE-2008-5881Proof of concept | Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directplaysms · playsms · CWE-22 | Высокая7,5 | — | 7,3 % | 9 янв. 2009 г. |
30Наблюдать | CVE-2004-2263Proof of concept | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statementsplaysms · playsms | Высокая7,5 | — | 1,4 % | 31 дек. 2004 г. |
26Наблюдать | CVE-2020-15018Эксплойта нет | playSMS through 1.4.3 is vulnerable to session fixation.playsms · playsms · CWE-384 | Средняя6,5 | — | 0,9 % | 24 июн. 2020 г. |
25Наблюдать | CVE-2024-8880Эксплойта нет | playSMS Template index.php code injectionplaysms · playsms · CWE-94 | Средняя6,3 | — | 0,7 % | 15 сент. 2024 г. |
20Наблюдать | CVE-2024-6469Эксплойта нет | playSMS Template injectionplaysms · playsms · CWE-74 | Средняя5,1 | — | 0,7 % | 3 июл. 2024 г. |
20Наблюдать | CVE-2024-6470Эксплойта нет | playSMS Template injectionplaysms · playsms · CWE-74 | Средняя5,1 | — | 0,4 % | 3 июл. 2024 г. |
20Наблюдать | CVE-2024-6251Эксплойта нет | playSMS New Phonebook cross site scriptingplaysms · playsms · CWE-80 | Средняя5,1 | — | 0,4 % | 22 июн. 2024 г. |
18Наблюдать | CVE-2005-4432Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the playsms · playsms | Средняя4,3 | — | 2,0 % | 20 дек. 2005 г. |
- CVE-2020-864495Срочно
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %playsms · playsms5 февр. 2020 г.
- CVE-2017-910162На этой неделе
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a
КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %playsms · playsms21 мая 2017 г.
- CVE-2017-908054В плане
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %playsms · playsms19 мая 2017 г.
- CVE-2021-4037340В плане
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut
КритическаяCVSS 9,8Proof of conceptEPSS 5 %playsms · playsms10 сент. 2021 г.
- CVE-2022-4703439Наблюдать
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %playsms · playsms13 февр. 2023 г.
- CVE-2009-010333Наблюдать
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %playsms · playsms9 янв. 2009 г.
- CVE-2008-588132Наблюдать
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %playsms · playsms9 янв. 2009 г.
- CVE-2004-226330Наблюдать
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %playsms · playsms31 дек. 2004 г.
- CVE-2020-1501826Наблюдать
playSMS through 1.4.3 is vulnerable to session fixation.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %playsms · playsms24 июн. 2020 г.
- CVE-2024-888025Наблюдать
playSMS Template index.php code injection
СредняяCVSS 6,3Эксплойта нетEPSS 1 %playsms · playsms15 сент. 2024 г.
- CVE-2024-646920Наблюдать
playSMS Template injection
СредняяCVSS 5,1Эксплойта нетEPSS 1 %playsms · playsms3 июл. 2024 г.
- CVE-2024-647020Наблюдать
playSMS Template injection
СредняяCVSS 5,1Эксплойта нетEPSS 0 %playsms · playsms3 июл. 2024 г.
- CVE-2024-625120Наблюдать
playSMS New Phonebook cross site scripting
СредняяCVSS 5,1Эксплойта нетEPSS 0 %playsms · playsms22 июн. 2024 г.
- CVE-2005-443218Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 2 %playsms · playsms20 дек. 2005 г.