Записи pyplate
5 опубликованных записей вендора pyplate.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
27Наблюдать | CVE-2014-3854Proof of concept | Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication opyplate · pyplate · CWE-352 | Средняя6,8 | — | 0,9 % | 7 авг. 2014 г. |
21Наблюдать | CVE-2014-3855Эксплойта нет | Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a ..pyplate · pyplate · CWE-22 | Средняя5,0 | — | 1,8 % | 7 авг. 2014 г. |
20Наблюдать | CVE-2014-3852Эксплойта нет | Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtapyplate · pyplate · CWE-200 | Средняя5,0 | — | 1,6 % | 7 авг. 2014 г. |
20Наблюдать | CVE-2014-3853Эксплойта нет | Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this pyplate · pyplate · CWE-200 | Средняя5,0 | — | 1,3 % | 7 авг. 2014 г. |
8Наблюдать | CVE-2014-3851Эксплойта нет | usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the pyplate · pyplate · CWE-200 | Низкая2,1 | — | 0,4 % | 7 авг. 2014 г. |
- CVE-2014-385427Наблюдать
Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication o
СредняяCVSS 6,8Proof of conceptEPSS 1 %pyplate · pyplate7 авг. 2014 г.
- CVE-2014-385521Наблюдать
Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pyplate · pyplate7 авг. 2014 г.
- CVE-2014-385220Наблюдать
Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obta
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pyplate · pyplate7 авг. 2014 г.
- CVE-2014-385320Наблюдать
Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pyplate · pyplate7 авг. 2014 г.
- CVE-2014-38518Наблюдать
usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pyplate · pyplate7 авг. 2014 г.