compassplus kayıtları
compassplus üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-611 Improper Restriction of XML External Entity Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2021-28110İstismar yok | /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.compassplus · tranzware e-commerce payment gateway · CWE-611 | Yüksek7,5 | — | %1,0 | 19 Mar 2021 |
24İzleyin | CVE-2021-28109İstismar yok | TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).compassplus · tranzware fimi · CWE-79 | Orta6,1 | — | %0,7 | 18 Mar 2021 |
24İzleyin | CVE-2021-43106İstismar yok | A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2compassplus · tranzware online · CWE-116 | Orta6,1 | — | %0,7 | 14 Şub 2022 |
24İzleyin | CVE-2021-28126İstismar yok | index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerabilitycompassplus · tranzware e-commerce payment gateway · CWE-79 | Orta6,1 | — | %0,6 | 19 Mar 2021 |
- CVE-2021-2811030İzleyin
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
YüksekCVSS 7,5İstismar yokEPSS %1compassplus · tranzware e-commerce payment gateway19 Mar 2021
- CVE-2021-2810924İzleyin
TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1compassplus · tranzware fimi18 Mar 2021
- CVE-2021-4310624İzleyin
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2
OrtaCVSS 6,1İstismar yokEPSS %1compassplus · tranzware online14 Şub 2022
- CVE-2021-2812624İzleyin
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %1compassplus · tranzware e-commerce payment gateway19 Mar 2021