Перейти к содержимому
Noroxi

Записи quickbox

5 опубликованных записей вендора quickbox.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 20
  2. 22

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

5 записей
  • CVE-2020-13448
    40В плане

    QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server

    ВысокаяCVSS 8,8Proof of conceptEPSS 17 %

    quickbox · quickbox1 июн. 2020 г.

  • CVE-2021-44981
    36Наблюдать

    In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec('');

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    quickbox · quickbox24 янв. 2022 г.

  • CVE-2020-13694
    36Наблюдать

    In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    quickbox · quickbox1 июн. 2020 г.

  • CVE-2020-13695
    29Наблюдать

    In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as ro

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    quickbox · quickbox1 июн. 2020 г.

  • CVE-2021-45281
    24Наблюдать

    QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input fo

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    quickbox · quickbox7 февр. 2022 г.