Записи quickbox
5 опубликованных записей вендора quickbox.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-269 Improper Privilege Management1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-13448Proof of concept | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the serverquickbox · quickbox · CWE-78 | Высокая8,8 | — | 17,4 % | 1 июн. 2020 г. |
36Наблюдать | CVE-2021-44981Эксплойта нет | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); quickbox · quickbox · CWE-78 | Высокая8,8 | — | 3,7 % | 24 янв. 2022 г. |
36Наблюдать | CVE-2020-13694Эксплойта нет | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a passwordquickbox · quickbox · CWE-78 | Высокая8,8 | — | 2,0 % | 1 июн. 2020 г. |
29Наблюдать | CVE-2020-13695Эксплойта нет | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as roquickbox · quickbox · CWE-269 | Высокая7,2 | — | 1,7 % | 1 июн. 2020 г. |
24Наблюдать | CVE-2021-45281Эксплойта нет | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input foquickbox · quickbox · CWE-79 | Средняя6,1 | — | 0,7 % | 7 февр. 2022 г. |
- CVE-2020-1344840В плане
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %quickbox · quickbox1 июн. 2020 г.
- CVE-2021-4498136Наблюдать
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec('');
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %quickbox · quickbox24 янв. 2022 г.
- CVE-2020-1369436Наблюдать
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %quickbox · quickbox1 июн. 2020 г.
- CVE-2020-1369529Наблюдать
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as ro
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %quickbox · quickbox1 июн. 2020 г.
- CVE-2021-4528124Наблюдать
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input fo
СредняяCVSS 6,1Эксплойта нетEPSS 1 %quickbox · quickbox7 февр. 2022 г.