comsenz kayıtları
comsenz üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-18083İstismar yok | An issue was discovered in DuomiCMS 3.0.comsenz · duomicms · CWE-94 | Kritik9,8 | — | %2,5 | 9 Eki 2018 |
39İzleyin | CVE-2018-18084İstismar yok | An issue was discovered in DuomiCMS 3.0.comsenz · duomicms · CWE-89 | Kritik9,8 | — | %1,3 | 9 Eki 2018 |
38İzleyin | CVE-2018-14729Kavram kanıtı | The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP comsenz · discuz\! · CWE-20 | Yüksek8,8 | — | %10,4 | 22 May 2019 |
32İzleyin | CVE-2018-20422İstismar yok | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#commoncomsenz · discuzx · CWE-287 | Yüksek8,1 | — | %1,3 | 24 Ara 2018 |
32İzleyin | CVE-2018-20423İstismar yok | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existcomsenz · discuzx | Yüksek8,1 | — | %1,2 | 24 Ara 2018 |
30İzleyin | CVE-2008-3554Kavram kanıtı | SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parametcomsenz · discuz · CWE-89 | Yüksek7,5 | — | %1,0 | 8 Ağu 2008 |
30İzleyin | CVE-2009-3185Kavram kanıtı | SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQcomsenz · crazy star plugin · CWE-89 | Yüksek7,5 | — | %1,0 | 15 Eyl 2009 |
28İzleyin | CVE-2008-6958Kavram kanıtı | wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula pcomsenz · crossday discuz\! board · CWE-94 | Orta6,5 | — | %5,8 | 12 Ağu 2009 |
23İzleyin | CVE-2018-20424İstismar yok | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbcomsenz · discuzx · CWE-20 | Orta5,9 | — | %0,9 | 24 Ara 2018 |
- CVE-2018-1808340Planlayın
An issue was discovered in DuomiCMS 3.0.
KritikCVSS 9,8İstismar yokEPSS %2comsenz · duomicms9 Eki 2018
- CVE-2018-1808439İzleyin
An issue was discovered in DuomiCMS 3.0.
KritikCVSS 9,8İstismar yokEPSS %1comsenz · duomicms9 Eki 2018
- CVE-2018-1472938İzleyin
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP
YüksekCVSS 8,8Kavram kanıtıEPSS %10comsenz · discuz\!22 May 2019
- CVE-2018-2042232İzleyin
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common
YüksekCVSS 8,1İstismar yokEPSS %1comsenz · discuzx24 Ara 2018
- CVE-2018-2042332İzleyin
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-exist
YüksekCVSS 8,1İstismar yokEPSS %1comsenz · discuzx24 Ara 2018
- CVE-2008-355430İzleyin
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %1comsenz · discuz8 Ağu 2008
- CVE-2009-318530İzleyin
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQ
YüksekCVSS 7,5Kavram kanıtıEPSS %1comsenz · crazy star plugin15 Eyl 2009
- CVE-2008-695828İzleyin
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula p
OrtaCVSS 6,5Kavram kanıtıEPSS %6comsenz · crossday discuz\! board12 Ağu 2009
- CVE-2018-2042423İzleyin
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unb
OrtaCVSS 5,9İstismar yokEPSS %1comsenz · discuzx24 Ara 2018