codologic kayıtları
codologic üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-13873İstismar yok | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authenticodologic · codoforum · CWE-89 | Kritik9,8 | — | %4,9 | 12 May 2021 |
38İzleyin | CVE-2022-31854Kavram kanıtı | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.codologic · codoforum · CWE-434 | Yüksek7,2 | — | %32,5 | 7 Tem 2022 |
28İzleyin | CVE-2020-22539İstismar yok | An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadicodologic · codoforum · CWE-434 | Yüksek7,2 | — | %0,9 | 15 Nis 2024 |
25İzleyin | CVE-2020-5842Kavram kanıtı | Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI.codologic · codoforum · CWE-79 | Orta6,1 | — | %1,8 | 7 Oca 2020 |
24İzleyin | CVE-2020-7051İstismar yok | Codologic Codoforum through 4.8.4 allows stored XSS in the login area.codologic · codoforum · CWE-79 | Orta6,1 | — | %0,8 | 13 Şub 2020 |
23İzleyin | CVE-2014-9261Kavram kanıtı | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackcodologic · codoforum · CWE-22 | Orta5,0 | — | %9,0 | 23 Mar 2015 |
21İzleyin | CVE-2020-7050İstismar yok | Codologic Codoforum through 4.8.4 allows a DOM-based XSS.codologic · codoforum · CWE-79 | Orta5,4 | — | %0,5 | 15 Şub 2020 |
21İzleyin | CVE-2020-9007İstismar yok | Codoforum 4.8.8 allows self-XSS via the title of a new topic.codologic · codoforum · CWE-79 | Orta5,4 | — | %0,5 | 16 Şub 2020 |
21İzleyin | CVE-2020-25875İstismar yok | A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbcodologic · codoforum · CWE-79 | Orta5,4 | — | %0,5 | 9 Tem 2021 |
21İzleyin | CVE-2020-25879İstismar yok | A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to executcodologic · codoforum · CWE-79 | Orta5,4 | — | %0,5 | 9 Tem 2021 |
21İzleyin | CVE-2020-25876İstismar yok | A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitcodologic · codoforum · CWE-79 | Orta5,4 | — | %0,5 | 9 Tem 2021 |
21İzleyin | CVE-2020-22540İstismar yok | Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive informaticodologic · codoforum · CWE-79 | Orta5,4 | — | %0,4 | 15 Nis 2024 |
19İzleyin | CVE-2020-5306İstismar yok | Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.codologic · codoforum · CWE-79 | Orta4,8 | — | %1,1 | 5 Oca 2020 |
19İzleyin | CVE-2020-5305İstismar yok | Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.codologic · codoforum · CWE-79 | Orta4,8 | — | %0,6 | 5 Oca 2020 |
19İzleyin | CVE-2020-5843İstismar yok | Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.codologic · codoforum · CWE-79 | Orta4,8 | — | %0,5 | 7 Oca 2020 |
18İzleyin | CVE-2013-5952İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow rejoomla · joomla\! · CWE-79 | Orta4,3 | — | %1,9 | 19 Mar 2014 |
- CVE-2020-1387340Planlayın
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authenti
KritikCVSS 9,8İstismar yokEPSS %5codologic · codoforum12 May 2021
- CVE-2022-3185438İzleyin
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
YüksekCVSS 7,2Kavram kanıtıEPSS %32codologic · codoforum7 Tem 2022
- CVE-2020-2253928İzleyin
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadi
YüksekCVSS 7,2İstismar yokEPSS %1codologic · codoforum15 Nis 2024
- CVE-2020-584225İzleyin
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI.
OrtaCVSS 6,1Kavram kanıtıEPSS %2codologic · codoforum7 Oca 2020
- CVE-2020-705124İzleyin
Codologic Codoforum through 4.8.4 allows stored XSS in the login area.
OrtaCVSS 6,1İstismar yokEPSS %1codologic · codoforum13 Şub 2020
- CVE-2014-926123İzleyin
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attack
OrtaCVSS 5,0Kavram kanıtıEPSS %9codologic · codoforum23 Mar 2015
- CVE-2020-705021İzleyin
Codologic Codoforum through 4.8.4 allows a DOM-based XSS.
OrtaCVSS 5,4İstismar yokEPSS %1codologic · codoforum15 Şub 2020
- CVE-2020-900721İzleyin
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
OrtaCVSS 5,4İstismar yokEPSS %1codologic · codoforum16 Şub 2020
- CVE-2020-2587521İzleyin
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arb
OrtaCVSS 5,4İstismar yokEPSS %1codologic · codoforum9 Tem 2021
- CVE-2020-2587921İzleyin
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execut
OrtaCVSS 5,4İstismar yokEPSS %0codologic · codoforum9 Tem 2021
- CVE-2020-2587621İzleyin
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbit
OrtaCVSS 5,4İstismar yokEPSS %0codologic · codoforum9 Tem 2021
- CVE-2020-2254021İzleyin
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive informati
OrtaCVSS 5,4İstismar yokEPSS %0codologic · codoforum15 Nis 2024
- CVE-2020-530619İzleyin
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
OrtaCVSS 4,8İstismar yokEPSS %1codologic · codoforum5 Oca 2020
- CVE-2020-530519İzleyin
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
OrtaCVSS 4,8İstismar yokEPSS %1codologic · codoforum5 Oca 2020
- CVE-2020-584319İzleyin
Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
OrtaCVSS 4,8İstismar yokEPSS %1codologic · codoforum7 Oca 2020
- CVE-2013-595218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow re
OrtaCVSS 4,3İstismar yokEPSS %2joomla · joomla\!19 Mar 2014