Перейти к содержимому
Noroxi

Записи Tecnick

26 опубликованных записей вендора tecnick.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
7,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2018-17057
    47В плане

    An issue was discovered in TCPDF before 6.2.22.

    КритическаяCVSS 9,8Proof of conceptEPSS 26 %

    tecnick · tcpdf14 сент. 2018 г.

  • CVE-2021-20114
    32Наблюдать

    When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ direc

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    tecnick · tcexam30 июл. 2021 г.

  • CVE-2009-4747
    31Наблюдать

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote atta

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    tecnick · aiocp26 мар. 2010 г.

  • CVE-2009-3220
    31Наблюдать

    PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute ar

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    tecnick · aiocp16 сент. 2009 г.

  • CVE-2010-2153
    29Наблюдать

    Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attacker

    СредняяCVSS 6,8Proof of conceptEPSS 7 %

    tecnick · tcexam3 июн. 2010 г.

  • CVE-2020-5745
    29Наблюдать

    Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users i

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2012-4237
    28Наблюдать

    Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exe

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    tecnick · tcexam20 авг. 2012 г.

  • CVE-2023-6554
    26Наблюдать

    Missing authorisation in TCExam

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    tecnick · tcexam11 янв. 2024 г.

  • CVE-2012-4601
    24Наблюдать

    Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permi

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    tecnick · tcexam23 нояб. 2012 г.

  • CVE-2020-5750
    24Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2020-5748
    24Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2021-20115
    24Наблюдать

    A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    tecnick · tcexam5 авг. 2021 г.

  • CVE-2021-20116
    24Наблюдать

    A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    tecnick · tcexam5 авг. 2021 г.

  • CVE-2018-13422
    24Наблюдать

    TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    tecnick · tcexam7 июл. 2018 г.

  • CVE-2021-20113
    21Наблюдать

    An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    tecnick · tcexam30 июл. 2021 г.

  • CVE-2020-5747
    21Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2020-5746
    21Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2020-5749
    21Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2020-5751
    21Наблюдать

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2021-20112
    21Наблюдать

    A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam30 июл. 2021 г.

  • CVE-2021-20111
    21Наблюдать

    A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    tecnick · tcexam30 июл. 2021 г.

  • CVE-2011-3806
    20Наблюдать

    TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    tecnick · tcexam23 сент. 2011 г.

  • CVE-2020-5744
    19Наблюдать

    Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

    СредняяCVSS 4,9Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.

  • CVE-2012-4602
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow re

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    tecnick · tcexam23 нояб. 2012 г.

  • CVE-2020-5743
    17Наблюдать

    Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    tecnick · tcexam7 мая 2020 г.