bigtreecms kayıtları
bigtreecms üreticisine ait 45 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
45 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-10574İstismar yok | site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the Bbigtreecms · bigtree cms · CWE-94 | Kritik9,8 | — | %2,2 | 30 Nis 2018 |
40Planlayın | CVE-2017-7695İstismar yok | Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety chbigtreecms · bigtree cms · CWE-434 | Kritik9,8 | — | %2,0 | 11 Nis 2017 |
39İzleyin | CVE-2017-9364İstismar yok | Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a bigtreecms · bigtree cms · CWE-434 | Kritik9,8 | — | %1,3 | 2 Haz 2017 |
36İzleyin | CVE-2017-9442İstismar yok | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web sbigtreecms · bigtree cms · CWE-94 | Yüksek8,8 | — | %2,5 | 5 Haz 2017 |
36İzleyin | CVE-2020-26670İstismar yok | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands tbigtreecms · bigtree cms · CWE-78 | Yüksek8,8 | — | %1,8 | 1 Haz 2021 |
35İzleyin | CVE-2017-9427İstismar yok | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\adminbigtreecms · bigtree cms · CWE-89 | Yüksek8,8 | — | %1,6 | 4 Haz 2017 |
35İzleyin | CVE-2020-26668İstismar yok | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacbigtreecms · bigtree cms · CWE-89 | Yüksek8,8 | — | %1,4 | 1 Haz 2021 |
35İzleyin | CVE-2017-9443İstismar yok | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json ibigtreecms · bigtree cms · CWE-89 | Yüksek8,8 | — | %1,3 | 5 Haz 2017 |
35İzleyin | CVE-2017-9449İstismar yok | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/adminbigtreecms · bigtree cms · CWE-89 | Yüksek8,8 | — | %1,1 | 6 Haz 2017 |
35İzleyin | CVE-2017-11736İstismar yok | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbibigtreecms · bigtree cms · CWE-89 | Yüksek8,8 | — | %1,0 | 29 Tem 2017 |
35İzleyin | CVE-2017-7881İstismar yok | BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing thbigtreecms · bigtree cms · CWE-352 | Yüksek8,8 | — | %0,8 | 15 Nis 2017 |
35İzleyin | CVE-2017-9365İstismar yok | CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fobigtreecms · bigtree cms · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Haz 2017 |
35İzleyin | CVE-2017-9379İstismar yok | Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.pbigtreecms · bigtree cms · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Haz 2017 |
35İzleyin | CVE-2017-9444İstismar yok | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.pbigtreecms · bigtree cms · CWE-352 | Yüksek8,8 | — | %0,5 | 5 Haz 2017 |
33İzleyin | CVE-2018-17341İstismar yok | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ subigtreecms · bigtree cms · CWE-287 | Yüksek8,1 | — | %1,9 | 23 Eyl 2018 |
31İzleyin | CVE-2013-4879Kavram kanıtı | SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL bigtreecms · bigtree cms · CWE-89 | Yüksek7,5 | — | %2,3 | 14 Ağu 2013 |
31İzleyin | CVE-2018-17030İstismar yok | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-bigtreecms · bigtree cms · CWE-94 | Yüksek7,5 | — | %2,3 | 13 Eyl 2018 |
31İzleyin | CVE-2017-9428İstismar yok | A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windowsbigtreecms · bigtree cms · CWE-22 | Yüksek7,5 | — | %2,0 | 4 Haz 2017 |
28İzleyin | CVE-2013-4881Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Orta6,8 | — | %2,2 | 19 Ağu 2013 |
28İzleyin | CVE-2017-6914İstismar yok | CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.bigtreecms · bigtree cms · CWE-352 | Yüksek7,1 | — | %0,4 | 15 Mar 2017 |
27İzleyin | CVE-2013-5313İstismar yok | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Orta6,8 | — | %0,9 | 19 Ağu 2013 |
26İzleyin | CVE-2017-16961İstismar yok | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain infbigtreecms · bigtree cms · CWE-89 | Orta6,5 | — | %1,4 | 27 Kas 2017 |
26İzleyin | CVE-2017-9378İstismar yok | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.bigtreecms · bigtree cms · CWE-863 | Orta6,5 | — | %0,6 | 2 Haz 2017 |
25İzleyin | CVE-2018-18308Kavram kanıtı | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload abigtreecms · bigtree cms · CWE-79 | Orta6,1 | — | %3,6 | 16 Eki 2018 |
24İzleyin | CVE-2018-1000521İstismar yok | BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vubigtreecms · bigtree cms · CWE-79 | Orta6,1 | — | %0,9 | 26 Haz 2018 |
- CVE-2018-1057440Planlayın
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B
KritikCVSS 9,8İstismar yokEPSS %2bigtreecms · bigtree cms30 Nis 2018
- CVE-2017-769540Planlayın
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch
KritikCVSS 9,8İstismar yokEPSS %2bigtreecms · bigtree cms11 Nis 2017
- CVE-2017-936439İzleyin
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a
KritikCVSS 9,8İstismar yokEPSS %1bigtreecms · bigtree cms2 Haz 2017
- CVE-2017-944236İzleyin
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s
YüksekCVSS 8,8İstismar yokEPSS %2bigtreecms · bigtree cms5 Haz 2017
- CVE-2020-2667036İzleyin
A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t
YüksekCVSS 8,8İstismar yokEPSS %2bigtreecms · bigtree cms1 Haz 2021
- CVE-2017-942735İzleyin
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin
YüksekCVSS 8,8İstismar yokEPSS %2bigtreecms · bigtree cms4 Haz 2017
- CVE-2020-2666835İzleyin
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac
YüksekCVSS 8,8İstismar yokEPSS %1bigtreecms · bigtree cms1 Haz 2021
- CVE-2017-944335İzleyin
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i
YüksekCVSS 8,8İstismar yokEPSS %1bigtreecms · bigtree cms5 Haz 2017
- CVE-2017-944935İzleyin
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin
YüksekCVSS 8,8İstismar yokEPSS %1bigtreecms · bigtree cms6 Haz 2017
- CVE-2017-1173635İzleyin
SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi
YüksekCVSS 8,8İstismar yokEPSS %1bigtreecms · bigtree cms29 Tem 2017
- CVE-2017-788135İzleyin
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th
YüksekCVSS 8,8İstismar yokEPSS %1bigtreecms · bigtree cms15 Nis 2017
- CVE-2017-936535İzleyin
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo
YüksekCVSS 8,8İstismar yokEPSS %0bigtreecms · bigtree cms2 Haz 2017
- CVE-2017-937935İzleyin
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p
YüksekCVSS 8,8İstismar yokEPSS %0bigtreecms · bigtree cms2 Haz 2017
- CVE-2017-944435İzleyin
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p
YüksekCVSS 8,8İstismar yokEPSS %0bigtreecms · bigtree cms5 Haz 2017
- CVE-2018-1734133İzleyin
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su
YüksekCVSS 8,1İstismar yokEPSS %2bigtreecms · bigtree cms23 Eyl 2018
- CVE-2013-487931İzleyin
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL
YüksekCVSS 7,5Kavram kanıtıEPSS %2bigtreecms · bigtree cms14 Ağu 2013
- CVE-2018-1703031İzleyin
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-
YüksekCVSS 7,5İstismar yokEPSS %2bigtreecms · bigtree cms13 Eyl 2018
- CVE-2017-942831İzleyin
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows
YüksekCVSS 7,5İstismar yokEPSS %2bigtreecms · bigtree cms4 Haz 2017
- CVE-2013-488128İzleyin
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
OrtaCVSS 6,8Kavram kanıtıEPSS %2bigtreecms · bigtree cms19 Ağu 2013
- CVE-2017-691428İzleyin
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.
YüksekCVSS 7,1İstismar yokEPSS %0bigtreecms · bigtree cms15 Mar 2017
- CVE-2013-531327İzleyin
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
OrtaCVSS 6,8İstismar yokEPSS %1bigtreecms · bigtree cms19 Ağu 2013
- CVE-2017-1696126İzleyin
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf
OrtaCVSS 6,5İstismar yokEPSS %1bigtreecms · bigtree cms27 Kas 2017
- CVE-2017-937826İzleyin
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.
OrtaCVSS 6,5İstismar yokEPSS %1bigtreecms · bigtree cms2 Haz 2017
- CVE-2018-1830825İzleyin
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a
OrtaCVSS 6,1Kavram kanıtıEPSS %4bigtreecms · bigtree cms16 Eki 2018
- CVE-2018-100052124İzleyin
BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu
OrtaCVSS 6,1İstismar yokEPSS %1bigtreecms · bigtree cms26 Haz 2018