Записи sdcms
6 опубликованных записей вендора sdcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-9651Эксплойта нет | An issue was discovered in SDCMS V1.7.sdcms · sdcms · CWE-94 | Критическая9,8 | — | 2,6 % | 10 мар. 2019 г. |
36Наблюдать | CVE-2018-19520Эксплойта нет | An issue was discovered in SDCMS 1.6 with PHP 5.x.sdcms · sdcms · CWE-94 | Высокая8,8 | — | 2,9 % | 25 нояб. 2018 г. |
35Наблюдать | CVE-2024-50809Эксплойта нет | The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commandsCWE-78 | Высокая8,8 | — | 0,7 % | 8 нояб. 2024 г. |
35Наблюдать | CVE-2019-9652Эксплойта нет | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request.sdcms · sdcms · CWE-352 | Высокая8,8 | — | 0,6 % | 10 мар. 2019 г. |
35Наблюдать | CVE-2018-11004Эксплойта нет | An issue was discovered in SDcms v1.5.sdcms · sdcms · CWE-352 | Высокая8,8 | — | 0,6 % | 12 мая 2018 г. |
31Наблюдать | CVE-2018-19748Эксплойта нет | app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&rsdcms · sdcms · CWE-22 | Высокая7,5 | — | 2,0 % | 29 нояб. 2018 г. |
- CVE-2019-965140В плане
An issue was discovered in SDCMS V1.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sdcms · sdcms10 мар. 2019 г.
- CVE-2018-1952036Наблюдать
An issue was discovered in SDCMS 1.6 with PHP 5.x.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %sdcms · sdcms25 нояб. 2018 г.
- CVE-2024-5080935Наблюдать
The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %8 нояб. 2024 г.
- CVE-2019-965235Наблюдать
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sdcms · sdcms10 мар. 2019 г.
- CVE-2018-1100435Наблюдать
An issue was discovered in SDcms v1.5.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sdcms · sdcms12 мая 2018 г.
- CVE-2018-1974831Наблюдать
app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&r
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sdcms · sdcms29 нояб. 2018 г.