5none kayıtları
5none üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %8,3
- Silahlaştırılmış
- 1 · %8,3
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 1058 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2018-20062Silahlaştırılmış | An issue was discovered in NoneCms V1.3.5none · nonecms | Kritik9,8 | KEV | %99,5 | 11 Ara 2018 |
35İzleyin | CVE-2018-7219İstismar yok | application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p5none · nonecms · CWE-352 | Yüksek8,8 | — | %0,5 | 19 Şub 2018 |
30İzleyin | CVE-2020-18646İstismar yok | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".5none · nonecms · CWE-668 | Yüksek7,5 | — | %1,5 | 22 Haz 2021 |
30İzleyin | CVE-2020-18647İstismar yok | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".5none · nonecms · CWE-668 | Yüksek7,5 | — | %1,5 | 22 Haz 2021 |
30İzleyin | CVE-2018-6029İstismar yok | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and5none · nonecms · CWE-918 | Yüksek7,5 | — | %1,4 | 23 Oca 2018 |
26İzleyin | CVE-2018-6022İstismar yok | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del5none · nonecms · CWE-22 | Orta6,5 | — | %1,4 | 23 Oca 2018 |
26İzleyin | CVE-2019-16721İstismar yok | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.5none · nonecms · CWE-352 | Orta6,5 | — | %0,5 | 23 Eyl 2019 |
24İzleyin | CVE-2020-23371İstismar yok | Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo5none · nonecms · CWE-79 | Orta6,1 | — | %0,9 | 10 May 2021 |
24İzleyin | CVE-2020-18282İstismar yok | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur5none · nonecms · CWE-79 | Orta6,1 | — | %0,5 | 8 May 2023 |
24İzleyin | CVE-2020-23376İstismar yok | NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj5none · nonecms · CWE-352 | Orta6,1 | — | %0,4 | 10 May 2021 |
21İzleyin | CVE-2020-23373İstismar yok | Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w5none · nonecms · CWE-79 | Orta5,4 | — | %0,8 | 10 May 2021 |
21İzleyin | CVE-2020-23374İstismar yok | Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra5none · nonecms · CWE-79 | Orta5,4 | — | %0,8 | 10 May 2021 |
- CVE-2018-2006299Hemen
An issue was discovered in NoneCms V1.3.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %1005none · nonecms11 Ara 2018
- CVE-2018-721935İzleyin
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p
YüksekCVSS 8,8İstismar yokEPSS %15none · nonecms19 Şub 2018
- CVE-2020-1864630İzleyin
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
YüksekCVSS 7,5İstismar yokEPSS %25none · nonecms22 Haz 2021
- CVE-2020-1864730İzleyin
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
YüksekCVSS 7,5İstismar yokEPSS %25none · nonecms22 Haz 2021
- CVE-2018-602930İzleyin
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and
YüksekCVSS 7,5İstismar yokEPSS %15none · nonecms23 Oca 2018
- CVE-2018-602226İzleyin
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del
OrtaCVSS 6,5İstismar yokEPSS %15none · nonecms23 Oca 2018
- CVE-2019-1672126İzleyin
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
OrtaCVSS 6,5İstismar yokEPSS %15none · nonecms23 Eyl 2019
- CVE-2020-2337124İzleyin
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo
OrtaCVSS 6,1İstismar yokEPSS %15none · nonecms10 May 2021
- CVE-2020-1828224İzleyin
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur
OrtaCVSS 6,1İstismar yokEPSS %15none · nonecms8 May 2023
- CVE-2020-2337624İzleyin
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj
OrtaCVSS 6,1İstismar yokEPSS %05none · nonecms10 May 2021
- CVE-2020-2337321İzleyin
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w
OrtaCVSS 5,4İstismar yokEPSS %15none · nonecms10 May 2021
- CVE-2020-2337421İzleyin
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra
OrtaCVSS 5,4İstismar yokEPSS %15none · nonecms10 May 2021