Записи Pluck
5 опубликованных записей вендора pluck.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
28Наблюдать | CVE-2008-3194Proof of concept | Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include anpluck · pluck · CWE-22 | Средняя6,8 | — | 2,6 % | 16 июл. 2008 г. |
27Наблюдать | CVE-2007-4181Эксплойта нет | PHP remote file inclusion vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to exepluck · pluck | Средняя6,8 | — | 1,6 % | 7 авг. 2007 г. |
22Наблюдать | CVE-2008-3851Proof of concept | Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local filpluck · pluck · CWE-22 | Средняя5,0 | — | 7,9 % | 27 авг. 2008 г. |
20Наблюдать | CVE-2007-4180Эксплойта нет | Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbipluck · pluck | Средняя5,0 | — | 1,5 % | 7 авг. 2007 г. |
10Наблюдать | CVE-2008-3574Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitpluck · pluck · CWE-79 | Низкая2,6 | — | 1,5 % | 10 авг. 2008 г. |
- CVE-2008-319428Наблюдать
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include an
СредняяCVSS 6,8Proof of conceptEPSS 3 %pluck · pluck16 июл. 2008 г.
- CVE-2007-418127Наблюдать
PHP remote file inclusion vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to exe
СредняяCVSS 6,8Эксплойта нетEPSS 2 %pluck · pluck7 авг. 2007 г.
- CVE-2008-385122Наблюдать
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local fil
СредняяCVSS 5,0Proof of conceptEPSS 8 %pluck · pluck27 авг. 2008 г.
- CVE-2007-418020Наблюдать
Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbi
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pluck · pluck7 авг. 2007 г.
- CVE-2008-357410Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbit
НизкаяCVSS 2,6Proof of conceptEPSS 2 %pluck · pluck10 авг. 2008 г.