Записи std42
16 опубликованных записей вендора std42.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 12,5 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2019-9194Готовый эксплойт | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.std42 · elfinder · CWE-78 | Критическая9,8 | — | 96,7 % | 26 февр. 2019 г. |
60На этой неделе | CVE-2021-32682Готовый эксплойт | Multiple vulnerabilities leading to RCEstd42 · elfinder · CWE-22 | Критическая9,8 | — | 69,9 % | 14 июн. 2021 г. |
52В плане | CVE-2021-43421Proof of concept | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to std42 · elfinder · CWE-434 | Критическая9,8 | — | 42,8 % | 7 апр. 2022 г. |
51В плане | CVE-2022-26960Proof of concept | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.std42 · elfinder · CWE-22 | Критическая9,1 | — | 51,0 % | 21 мар. 2022 г. |
48В плане | CVE-2022-27115Эксплойта нет | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.std42 · elfinder · CWE-434 | Критическая9,8 | — | 28,6 % | 11 апр. 2022 г. |
45В плане | CVE-2021-23394Proof of concept | Remote Code Execution (RCE)std42 · elfinder · CWE-434 | Критическая9,8 | — | 18,9 % | 13 июн. 2021 г. |
39Наблюдать | CVE-2023-52044Эксплойта нет | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensistd42 · elfinder · CWE-434 | Критическая9,8 | — | 0,8 % | 31 окт. 2024 г. |
39Наблюдать | CVE-2024-38909Эксплойта нет | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.std42 · elfinder · CWE-284 | Критическая9,8 | — | 0,5 % | 30 июл. 2024 г. |
37Наблюдать | CVE-2018-9109Эксплойта нет | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Критическая9,1 | — | 2,9 % | 28 мар. 2018 г. |
37Наблюдать | CVE-2018-9110Эксплойта нет | Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Критическая9,1 | — | 2,9 % | 28 мар. 2018 г. |
36Наблюдать | CVE-2026-41247Эксплойта нет | elFinder: Command injection in resize background color parameter when using ImageMagick CLIstd42 · elfinder · CWE-78 | Высокая8,9 | — | 2,7 % | 23 апр. 2026 г. |
30Наблюдать | CVE-2019-6257Эксплойта нет | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal std42 · elfinder · CWE-918 | Высокая7,7 | — | 1,1 % | 14 янв. 2019 г. |
27Наблюдать | CVE-2023-35840Proof of concept | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.std42 · elfinder · CWE-22 | Средняя6,5 | — | 1,9 % | 18 июн. 2023 г. |
24Наблюдать | CVE-2023-52045Эксплойта нет | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.std42 · elfinder · CWE-79 | Средняя6,1 | — | 0,3 % | 31 окт. 2024 г. |
23Наблюдать | CVE-2019-5884Эксплойта нет | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not sstd42 · elfinder · CWE-200 | Средняя5,9 | — | 1,3 % | 10 янв. 2019 г. |
21Наблюдать | CVE-2021-45919Эксплойта нет | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.std42 · elfinder · CWE-79 | Средняя5,4 | — | 0,6 % | 8 февр. 2022 г. |
- CVE-2019-919468На этой неделе
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %std42 · elfinder26 февр. 2019 г.
- CVE-2021-3268260На этой неделе
Multiple vulnerabilities leading to RCE
КритическаяCVSS 9,8Готовый эксплойтEPSS 70 %std42 · elfinder14 июн. 2021 г.
- CVE-2021-4342152В плане
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to
КритическаяCVSS 9,8Proof of conceptEPSS 43 %std42 · elfinder7 апр. 2022 г.
- CVE-2022-2696051В плане
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.
КритическаяCVSS 9,1Proof of conceptEPSS 51 %std42 · elfinder21 мар. 2022 г.
- CVE-2022-2711548В плане
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %std42 · elfinder11 апр. 2022 г.
- CVE-2021-2339445В плане
Remote Code Execution (RCE)
КритическаяCVSS 9,8Proof of conceptEPSS 19 %std42 · elfinder13 июн. 2021 г.
- CVE-2023-5204439Наблюдать
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %std42 · elfinder31 окт. 2024 г.
- CVE-2024-3890939Наблюдать
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %std42 · elfinder30 июл. 2024 г.
- CVE-2018-910937Наблюдать
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %std42 · elfinder28 мар. 2018 г.
- CVE-2018-911037Наблюдать
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %std42 · elfinder28 мар. 2018 г.
- CVE-2026-4124736Наблюдать
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
ВысокаяCVSS 8,9Эксплойта нетEPSS 3 %std42 · elfinder23 апр. 2026 г.
- CVE-2019-625730Наблюдать
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %std42 · elfinder14 янв. 2019 г.
- CVE-2023-3584027Наблюдать
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
СредняяCVSS 6,5Proof of conceptEPSS 2 %std42 · elfinder18 июн. 2023 г.
- CVE-2023-5204524Наблюдать
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %std42 · elfinder31 окт. 2024 г.
- CVE-2019-588423Наблюдать
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not s
СредняяCVSS 5,9Эксплойта нетEPSS 1 %std42 · elfinder10 янв. 2019 г.
- CVE-2021-4591921Наблюдать
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %std42 · elfinder8 февр. 2022 г.