İçeriğe atla
Noroxi

afian kayıtları

afian üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2022-30470
    40Planlayın

    In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code exe

    KritikCVSS 9,8İstismar yokEPSS %3

    afian · filerun2 Haz 2022

  • CVE-2022-30469
    35İzleyin

    In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL

    YüksekCVSS 8,8İstismar yokEPSS %1

    afian · filerun6 Haz 2022

  • CVE-2021-35504
    29İzleyin

    Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

    YüksekCVSS 7,2İstismar yokEPSS %3

    afian · filerun5 Eki 2021

  • CVE-2021-35505
    29İzleyin

    Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

    YüksekCVSS 7,2İstismar yokEPSS %3

    afian · filerun5 Eki 2021

  • CVE-2018-7734
    28İzleyin

    Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter i

    YüksekCVSS 7,2İstismar yokEPSS %1

    afian · filerun6 Mar 2018

  • CVE-2018-7735
    28İzleyin

    Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter i

    YüksekCVSS 7,2İstismar yokEPSS %1

    afian · filerun6 Mar 2018

  • CVE-2019-12905
    25İzleyin

    FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI.

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    afian · filerun20 Haz 2019

  • CVE-2021-35506
    24İzleyin

    Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit

    OrtaCVSS 6,1İstismar yokEPSS %1

    afian · filerun5 Eki 2021

  • CVE-2021-35503
    24İzleyin

    Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

    OrtaCVSS 6,1İstismar yokEPSS %1

    afian · filerun5 Eki 2021

  • CVE-2019-12458
    22İzleyin

    FileRun 2019.05.21 allows css/ext-ux Directory Listing.

    OrtaCVSS 5,3İstismar yokEPSS %2

    afian · filerun30 May 2019

  • CVE-2019-12459
    22İzleyin

    FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing.

    OrtaCVSS 5,3İstismar yokEPSS %2

    afian · filerun30 May 2019

  • CVE-2019-12457
    22İzleyin

    FileRun 2019.05.21 allows images/extjs Directory Listing.

    OrtaCVSS 5,3İstismar yokEPSS %2

    afian · filerun30 May 2019

  • CVE-2023-28875
    21İzleyin

    A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed whe

    OrtaCVSS 5,4İstismar yokEPSS %0

    afian · filerun5 Ara 2023

  • CVE-2023-28876
    17İzleyin

    A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files

    OrtaCVSS 4,3İstismar yokEPSS %0

    afian · filerun5 Ara 2023