Записи sitracker
22 опубликованных записей вендора sitracker.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 9,1 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2007-5635Эксплойта нет | Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.sitracker · support incident tracker | Критическая10,0 | — | 1,4 % | 23 окт. 2007 г. |
31Наблюдать | CVE-2011-4337Proof of concept | Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to injsitracker · support incident tracker · CWE-94 | Высокая7,5 | — | 2,4 % | 29 янв. 2012 г. |
31Наблюдать | CVE-2011-3831Эксплойта нет | SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitsitracker · support incident tracker · CWE-89 | Высокая7,5 | — | 1,7 % | 29 янв. 2012 г. |
30Наблюдать | CVE-2011-3833Готовый эксплойт | Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users sitracker · support incident tracker | Средняя6,0 | — | 19,0 % | 29 янв. 2012 г. |
30Наблюдать | CVE-2011-5071Proof of concept | Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL cositracker · support incident tracker · CWE-89 | Высокая7,5 | — | 1,0 % | 29 янв. 2012 г. |
30Наблюдать | CVE-2011-5072Proof of concept | Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL cositracker · support incident tracker · CWE-89 | Высокая7,5 | — | 1,0 % | 29 янв. 2012 г. |
27Наблюдать | CVE-2010-1596Эксплойта нет | Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication sitracker · support incident tracker · CWE-287 | Средняя6,8 | — | 1,5 % | 28 апр. 2010 г. |
27Наблюдать | CVE-2011-5074Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijasitracker · support incident tracker · CWE-352 | Средняя6,8 | — | 1,0 % | 29 янв. 2012 г. |
27Наблюдать | CVE-2011-5068Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the sitracker · support incident tracker · CWE-352 | Средняя6,8 | — | 0,7 % | 29 янв. 2012 г. |
26Наблюдать | CVE-2011-3832Эксплойта нет | Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to executesitracker · support incident tracker · CWE-94 | Средняя6,5 | — | 1,3 % | 29 янв. 2012 г. |
25Наблюдать | CVE-2011-5069Эксплойта нет | Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated usitracker · support incident tracker | Средняя6,0 | — | 1,9 % | 29 янв. 2012 г. |
24Наблюдать | CVE-2019-20223Эксплойта нет | In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVsitracker · support incident tracker · CWE-79 | Средняя6,1 | — | 0,7 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2019-20220Эксплойта нет | In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.sitracker · support incident tracker · CWE-79 | Средняя6,1 | — | 0,7 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2019-20221Эксплойта нет | In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.sitracker · support incident tracker · CWE-79 | Средняя6,1 | — | 0,7 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2019-20222Эксплойта нет | In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.sitracker · support incident tracker · CWE-79 | Средняя6,1 | — | 0,7 % | 2 янв. 2020 г. |
21Наблюдать | CVE-2011-3829Готовый эксплойт | ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the fisitracker · support incident tracker · CWE-200 | Средняя4,0 | — | 17,1 % | 29 янв. 2012 г. |
21Наблюдать | CVE-2011-5075Proof of concept | translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct sitracker · support incident tracker | Средняя5,0 | — | 2,6 % | 29 янв. 2012 г. |
18Наблюдать | CVE-2011-3830Эксплойта нет | Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitrasitracker · support incident tracker · CWE-79 | Средняя4,3 | — | 1,8 % | 29 янв. 2012 г. |
17Наблюдать | CVE-2011-5073Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbisitracker · support incident tracker · CWE-79 | Средняя4,3 | — | 1,5 % | 29 янв. 2012 г. |
17Наблюдать | CVE-2011-5070Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary wsitracker · support incident tracker · CWE-79 | Средняя4,3 | — | 1,5 % | 29 янв. 2012 г. |
17Наблюдать | CVE-2012-2235Эксплойта нет | Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary websitracker · support incident tracker · CWE-79 | Средняя4,3 | — | 1,0 % | 27 мая 2012 г. |
16Наблюдать | CVE-2011-5067Эксплойта нет | move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via thesitracker · support incident tracker · CWE-200 | Средняя4,0 | — | 0,9 % | 29 янв. 2012 г. |
- CVE-2007-563540В плане
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %sitracker · support incident tracker23 окт. 2007 г.
- CVE-2011-433731Наблюдать
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inj
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-383131Наблюдать
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbit
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-383330Наблюдать
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users
СредняяCVSS 6,0Готовый эксплойтEPSS 19 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-507130Наблюдать
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-507230Наблюдать
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2010-159627Наблюдать
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication
СредняяCVSS 6,8Эксплойта нетEPSS 2 %sitracker · support incident tracker28 апр. 2010 г.
- CVE-2011-507427Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hija
СредняяCVSS 6,8Proof of conceptEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-506827Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the
СредняяCVSS 6,8Эксплойта нетEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-383226Наблюдать
Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-506925Наблюдать
Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated u
СредняяCVSS 6,0Эксплойта нетEPSS 2 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2019-2022324Наблюдать
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CV
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sitracker · support incident tracker2 янв. 2020 г.
- CVE-2019-2022024Наблюдать
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sitracker · support incident tracker2 янв. 2020 г.
- CVE-2019-2022124Наблюдать
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sitracker · support incident tracker2 янв. 2020 г.
- CVE-2019-2022224Наблюдать
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sitracker · support incident tracker2 янв. 2020 г.
- CVE-2011-382921Наблюдать
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the fi
СредняяCVSS 4,0Готовый эксплойтEPSS 17 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-507521Наблюдать
translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct
СредняяCVSS 5,0Proof of conceptEPSS 3 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-383018Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitra
СредняяCVSS 4,3Эксплойта нетEPSS 2 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-507317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbi
СредняяCVSS 4,3Proof of conceptEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2011-507017Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary w
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.
- CVE-2012-223517Наблюдать
Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sitracker · support incident tracker27 мая 2012 г.
- CVE-2011-506716Наблюдать
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the
СредняяCVSS 4,0Эксплойта нетEPSS 1 %sitracker · support incident tracker29 янв. 2012 г.