ddsn kayıtları
ddsn üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-284 Improper Access Control1
- CWE-20 Improper Input Validation1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2025-63314Kavram kanıtı | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theddsn · cm3 acora cms · CWE-640 | Kritik10,0 | — | %0,3 | 12 Oca 2026 |
35İzleyin | CVE-2025-25967Kavram kanıtı | Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF).ddsn · acora cms · CWE-352 | Yüksek8,8 | — | %0,6 | 3 Mar 2025 |
32İzleyin | CVE-2025-22964Kavram kanıtı | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient inpddsn · cm3 acora content management system · CWE-89 | Yüksek8,1 | — | %0,9 | 15 Oca 2025 |
30İzleyin | CVE-2006-0221İstismar yok | SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remddsn · cm3cms | Yüksek7,5 | — | %1,2 | 16 Oca 2006 |
27İzleyin | CVE-2013-4726İstismar yok | Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly oddsn · cm3 acora content management system · CWE-352 | Orta6,8 | — | %1,1 | 25 Nis 2014 |
24İzleyin | CVE-2013-4723İstismar yok | Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allowsddsn · cm3 acora content management system · CWE-20 | Orta5,8 | — | %2,0 | 25 Nis 2014 |
24İzleyin | CVE-2025-25968Kavram kanıtı | DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability.ddsn · cm3 acora content management system · CWE-284 | Orta6,0 | — | %1,0 | 20 Şub 2025 |
21İzleyin | CVE-2013-4727Kavram kanıtı | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain seddsn · cm3 acora content management system · CWE-200 | Orta5,0 | — | %2,7 | 6 Haz 2014 |
20İzleyin | CVE-2013-4725İstismar yok | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an ddsn · cm3 acora content management system · CWE-200 | Orta5,0 | — | %1,2 | 6 Haz 2014 |
20İzleyin | CVE-2013-4728İstismar yok | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain seddsn · cm3 acora content management system · CWE-200 | Orta5,0 | — | %1,2 | 6 Haz 2014 |
20İzleyin | CVE-2013-4724İstismar yok | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag iddsn · cm3 acora content management system · CWE-200 | Orta5,0 | — | %1,2 | 6 Haz 2014 |
18İzleyin | CVE-2013-4722İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/1ddsn · cm3 acora content management system · CWE-79 | Orta4,3 | — | %1,9 | 25 Nis 2014 |
- CVE-2025-6331440Planlayın
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the
KritikCVSS 10,0Kavram kanıtıEPSS %0ddsn · cm3 acora cms12 Oca 2026
- CVE-2025-2596735İzleyin
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF).
YüksekCVSS 8,8Kavram kanıtıEPSS %1ddsn · acora cms3 Mar 2025
- CVE-2025-2296432İzleyin
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient inp
YüksekCVSS 8,1Kavram kanıtıEPSS %1ddsn · cm3 acora content management system15 Oca 2025
- CVE-2006-022130İzleyin
SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows rem
YüksekCVSS 7,5İstismar yokEPSS %1ddsn · cm3cms16 Oca 2006
- CVE-2013-472627İzleyin
Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly o
OrtaCVSS 6,8İstismar yokEPSS %1ddsn · cm3 acora content management system25 Nis 2014
- CVE-2013-472324İzleyin
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows
OrtaCVSS 5,8İstismar yokEPSS %2ddsn · cm3 acora content management system25 Nis 2014
- CVE-2025-2596824İzleyin
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability.
OrtaCVSS 6,0Kavram kanıtıEPSS %1ddsn · cm3 acora content management system20 Şub 2025
- CVE-2013-472721İzleyin
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain se
OrtaCVSS 5,0Kavram kanıtıEPSS %3ddsn · cm3 acora content management system6 Haz 2014
- CVE-2013-472520İzleyin
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an
OrtaCVSS 5,0İstismar yokEPSS %1ddsn · cm3 acora content management system6 Haz 2014
- CVE-2013-472820İzleyin
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain se
OrtaCVSS 5,0İstismar yokEPSS %1ddsn · cm3 acora content management system6 Haz 2014
- CVE-2013-472420İzleyin
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag i
OrtaCVSS 5,0İstismar yokEPSS %1ddsn · cm3 acora content management system6 Haz 2014
- CVE-2013-472218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/1
OrtaCVSS 4,3İstismar yokEPSS %2ddsn · cm3 acora content management system25 Nis 2014