Перейти к содержимому
Noroxi

Записи playsms

14 опубликованных записей вендора playsms.

Профиль для исследователя

Попали в KEV
1 · 7,1 %
С эксплойтом
3 · 21,4 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
637 дн.

Все записи

14 записей
  • CVE-2020-8644
    95Срочно

    PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %

    playsms · playsms5 февр. 2020 г.

  • CVE-2017-9101
    62На этой неделе

    import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a

    КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %

    playsms · playsms21 мая 2017 г.

  • CVE-2017-9080
    54В плане

    PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %

    playsms · playsms19 мая 2017 г.

  • CVE-2021-40373
    40В плане

    playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    playsms · playsms10 сент. 2021 г.

  • CVE-2022-47034
    39Наблюдать

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    playsms · playsms13 февр. 2023 г.

  • CVE-2009-0103
    33Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    playsms · playsms9 янв. 2009 г.

  • CVE-2008-5881
    32Наблюдать

    Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    playsms · playsms9 янв. 2009 г.

  • CVE-2004-2263
    30Наблюдать

    SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    playsms · playsms31 дек. 2004 г.

  • CVE-2020-15018
    26Наблюдать

    playSMS through 1.4.3 is vulnerable to session fixation.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    playsms · playsms24 июн. 2020 г.

  • CVE-2024-8880
    25Наблюдать

    playSMS Template index.php code injection

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    playsms · playsms15 сент. 2024 г.

  • CVE-2024-6469
    20Наблюдать

    playSMS Template injection

    СредняяCVSS 5,1Эксплойта нетEPSS 1 %

    playsms · playsms3 июл. 2024 г.

  • CVE-2024-6470
    20Наблюдать

    playSMS Template injection

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    playsms · playsms3 июл. 2024 г.

  • CVE-2024-6251
    20Наблюдать

    playSMS New Phonebook cross site scripting

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    playsms · playsms22 июн. 2024 г.

  • CVE-2005-4432
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    playsms · playsms20 дек. 2005 г.