Записи Tecnick
26 опубликованных записей вендора tecnick.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 7,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2018-17057Proof of concept | An issue was discovered in TCPDF before 6.2.22.tecnick · tcpdf · CWE-502 | Критическая9,8 | — | 26,2 % | 14 сент. 2018 г. |
32Наблюдать | CVE-2021-20114Proof of concept | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directecnick · tcexam · CWE-425 | Высокая7,5 | — | 6,0 % | 30 июл. 2021 г. |
31Наблюдать | CVE-2009-4747Proof of concept | PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attatecnick · aiocp · CWE-94 | Высокая7,5 | — | 3,0 % | 26 мар. 2010 г. |
31Наблюдать | CVE-2009-3220Proof of concept | PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute artecnick · aiocp · CWE-94 | Высокая7,5 | — | 2,1 % | 16 сент. 2009 г. |
29Наблюдать | CVE-2010-2153Proof of concept | Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackertecnick · tcexam | Средняя6,8 | — | 7,5 % | 3 июн. 2010 г. |
29Наблюдать | CVE-2020-5745Эксплойта нет | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users itecnick · tcexam · CWE-352 | Высокая7,4 | — | 0,8 % | 7 мая 2020 г. |
28Наблюдать | CVE-2012-4237Proof of concept | Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exetecnick · tcexam · CWE-89 | Средняя6,8 | — | 2,4 % | 20 авг. 2012 г. |
26Наблюдать | CVE-2023-6554Эксплойта нет | Missing authorisation in TCExamtecnick · tcexam · CWE-862 | Средняя6,5 | — | 0,6 % | 11 янв. 2024 г. |
24Наблюдать | CVE-2012-4601Эксплойта нет | Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permitecnick · tcexam · CWE-89 | Средняя6,0 | — | 1,6 % | 23 нояб. 2012 г. |
24Наблюдать | CVE-2020-5750Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Средняя6,1 | — | 1,1 % | 7 мая 2020 г. |
24Наблюдать | CVE-2020-5748Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Средняя6,1 | — | 1,1 % | 7 мая 2020 г. |
24Наблюдать | CVE-2021-20115Эксплойта нет | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.tecnick · tcexam · CWE-79 | Средняя6,1 | — | 0,9 % | 5 авг. 2021 г. |
24Наблюдать | CVE-2021-20116Эксплойта нет | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.tecnick · tcexam · CWE-79 | Средняя6,1 | — | 0,9 % | 5 авг. 2021 г. |
24Наблюдать | CVE-2018-13422Эксплойта нет | TCExam before 14.1.2 has XSS via an ff_ or xl_ field.tecnick · tcexam · CWE-79 | Средняя6,1 | — | 0,8 % | 7 июл. 2018 г. |
21Наблюдать | CVE-2021-20113Эксплойта нет | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-203 | Средняя5,3 | — | 1,3 % | 30 июл. 2021 г. |
21Наблюдать | CVE-2020-5747Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,7 % | 7 мая 2020 г. |
21Наблюдать | CVE-2020-5746Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,7 % | 7 мая 2020 г. |
21Наблюдать | CVE-2020-5749Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,7 % | 7 мая 2020 г. |
21Наблюдать | CVE-2020-5751Эксплойта нет | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,7 % | 7 мая 2020 г. |
21Наблюдать | CVE-2021-20112Эксплойта нет | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,6 % | 30 июл. 2021 г. |
21Наблюдать | CVE-2021-20111Эксплойта нет | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Средняя5,4 | — | 0,6 % | 30 июл. 2021 г. |
20Наблюдать | CVE-2011-3806Эксплойта нет | TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation tecnick · tcexam · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
19Наблюдать | CVE-2020-5744Эксплойта нет | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.tecnick · tcexam · CWE-22 | Средняя4,9 | — | 1,4 % | 7 мая 2020 г. |
18Наблюдать | CVE-2012-4602Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow retecnick · tcexam · CWE-79 | Средняя4,3 | — | 1,8 % | 23 нояб. 2012 г. |
17Наблюдать | CVE-2020-5743Эксплойта нет | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they dontecnick · tcexam · CWE-639 | Средняя4,3 | — | 0,8 % | 7 мая 2020 г. |
- CVE-2018-1705747В плане
An issue was discovered in TCPDF before 6.2.22.
КритическаяCVSS 9,8Proof of conceptEPSS 26 %tecnick · tcpdf14 сент. 2018 г.
- CVE-2021-2011432Наблюдать
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ direc
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %tecnick · tcexam30 июл. 2021 г.
- CVE-2009-474731Наблюдать
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote atta
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %tecnick · aiocp26 мар. 2010 г.
- CVE-2009-322031Наблюдать
PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute ar
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %tecnick · aiocp16 сент. 2009 г.
- CVE-2010-215329Наблюдать
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attacker
СредняяCVSS 6,8Proof of conceptEPSS 7 %tecnick · tcexam3 июн. 2010 г.
- CVE-2020-574529Наблюдать
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users i
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2012-423728Наблюдать
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exe
СредняяCVSS 6,8Proof of conceptEPSS 2 %tecnick · tcexam20 авг. 2012 г.
- CVE-2023-655426Наблюдать
Missing authorisation in TCExam
СредняяCVSS 6,5Эксплойта нетEPSS 1 %tecnick · tcexam11 янв. 2024 г.
- CVE-2012-460124Наблюдать
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permi
СредняяCVSS 6,0Эксплойта нетEPSS 2 %tecnick · tcexam23 нояб. 2012 г.
- CVE-2020-575024Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2020-574824Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2021-2011524Наблюдать
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tecnick · tcexam5 авг. 2021 г.
- CVE-2021-2011624Наблюдать
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tecnick · tcexam5 авг. 2021 г.
- CVE-2018-1342224Наблюдать
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tecnick · tcexam7 июл. 2018 г.
- CVE-2021-2011321Наблюдать
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %tecnick · tcexam30 июл. 2021 г.
- CVE-2020-574721Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2020-574621Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2020-574921Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2020-575121Наблюдать
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2021-2011221Наблюдать
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam30 июл. 2021 г.
- CVE-2021-2011121Наблюдать
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tecnick · tcexam30 июл. 2021 г.
- CVE-2011-380620Наблюдать
TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
СредняяCVSS 5,0Эксплойта нетEPSS 1 %tecnick · tcexam23 сент. 2011 г.
- CVE-2020-574419Наблюдать
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.
- CVE-2012-460218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow re
СредняяCVSS 4,3Эксплойта нетEPSS 2 %tecnick · tcexam23 нояб. 2012 г.
- CVE-2020-574317Наблюдать
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tecnick · tcexam7 мая 2020 г.