dedebiz kayıtları
dedebiz üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2023-31546Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.dedebiz · dedebiz · CWE-79 | Kritik9,6 | — | %49,4 | 13 Ara 2023 |
40Planlayın | CVE-2022-44118Kavram kanıtı | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.dedebiz · dedecmsv6 | Kritik9,8 | — | %1,8 | 23 Kas 2022 |
39İzleyin | CVE-2023-43234İstismar yok | DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $acdedebiz · dedebiz · CWE-94 | Kritik9,8 | — | %1,1 | 27 Eyl 2023 |
39İzleyin | CVE-2024-52770İstismar yok | An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary cdedebiz · dedebiz · CWE-79 | Kritik9,8 | — | %0,8 | 20 Kas 2024 |
39İzleyin | CVE-2022-44120İstismar yok | dedecmdv6 6.1.9 is vulnerable to SQL Injection.dedebiz · dedecmsv6 · CWE-89 | Kritik9,8 | — | %0,7 | 23 Kas 2022 |
36İzleyin | CVE-2022-43196İstismar yok | dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.dedebiz · dedecmsv6 | Kritik9,1 | — | %0,7 | 23 Kas 2022 |
36İzleyin | CVE-2024-52771İstismar yok | DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.dedebiz · dedebiz · CWE-22 | Kritik9,1 | — | %0,7 | 20 Kas 2024 |
35İzleyin | CVE-2023-5266İstismar yok | DedeBIZ tags_main.php sql injectiondedebiz · dedebiz · CWE-89 | Yüksek8,8 | — | %0,5 | 29 Eyl 2023 |
29İzleyin | CVE-2022-36215İstismar yok | DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.dedebiz · dedecmsv6 | Yüksek7,2 | — | %2,3 | 17 Ağu 2022 |
28İzleyin | CVE-2023-7181İstismar yok | Muyun DedeBIZ Add Attachment unrestricted uploaddedebiz · dedebiz · CWE-434 | Yüksek7,2 | — | %0,8 | 30 Ara 2023 |
28İzleyin | CVE-2024-52769İstismar yok | An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code dedebiz · dedebiz · CWE-434 | Yüksek7,2 | — | %0,7 | 20 Kas 2024 |
28İzleyin | CVE-2023-6755İstismar yok | DedeBIZ content_batchup_action.php sql injectiondedebiz · dedebiz · CWE-89 | Yüksek7,2 | — | %0,7 | 13 Ara 2023 |
28İzleyin | CVE-2023-3839İstismar yok | DedeBIZ sys_sql_query.php sql injectiondedebiz · dedebiz · CWE-89 | Yüksek7,2 | — | %0,7 | 22 Tem 2023 |
28İzleyin | CVE-2024-0558İstismar yok | DedeBIZ makehtml_freelist_action.php sql injectiondedebiz · dedebiz · CWE-89 | Yüksek7,2 | — | %0,6 | 15 Oca 2024 |
28İzleyin | CVE-2023-5268İstismar yok | DedeBIZ makehtml_taglist_action.php sql injectiondedebiz · dedebiz · CWE-89 | Yüksek7,2 | — | %0,5 | 29 Eyl 2023 |
24İzleyin | CVE-2024-44716İstismar yok | A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloaddedebiz · dedebiz · CWE-79 | Orta6,1 | — | %0,3 | 29 Ağu 2024 |
24İzleyin | CVE-2024-44717İstismar yok | A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloaddedebiz · dedebiz · CWE-79 | Orta6,1 | — | %0,3 | 29 Ağu 2024 |
21İzleyin | CVE-2024-7903İstismar yok | DedeBIZ File Extension media_add.php unrestricted uploaddedebiz · dedebiz · CWE-434 | Orta5,3 | — | %0,7 | 18 Ağu 2024 |
21İzleyin | CVE-2024-7904İstismar yok | DedeBIZ File Extension file_manage_control.php unrestricted uploaddedebiz · dedebiz · CWE-434 | Orta5,3 | — | %0,7 | 18 Ağu 2024 |
21İzleyin | CVE-2024-7905İstismar yok | DedeBIZ archives_do.php AdminUpload unrestricted uploaddedebiz · dedebiz · CWE-434 | Orta5,3 | — | %0,7 | 18 Ağu 2024 |
21İzleyin | CVE-2024-7906İstismar yok | DedeBIZ Attachment Settings select_images_post.php get_mime_type unrestricted uploaddedebiz · dedebiz · CWE-434 | Orta5,3 | — | %0,5 | 18 Ağu 2024 |
21İzleyin | CVE-2024-0557İstismar yok | DedeBIZ Website Copyright Setting cross site scriptingdedebiz · dedebiz · CWE-79 | Orta5,4 | — | %0,5 | 15 Oca 2024 |
21İzleyin | CVE-2023-43232İstismar yok | A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute adedebiz · dedebiz · CWE-79 | Orta5,4 | — | %0,4 | 27 Eyl 2023 |
19İzleyin | CVE-2023-3837İstismar yok | DedeBIZ sys_sql_query.php cross site scriptingdedebiz · dedebiz · CWE-79 | Orta4,8 | — | %0,7 | 22 Tem 2023 |
19İzleyin | CVE-2023-4170İstismar yok | DedeBIZ Article cross site scriptingdedebiz · dedebiz · CWE-79 | Orta4,8 | — | %0,6 | 5 Ağu 2023 |
- CVE-2023-3154653Planlayın
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
KritikCVSS 9,6Kavram kanıtıEPSS %49dedebiz · dedebiz13 Ara 2023
- CVE-2022-4411840Planlayın
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
KritikCVSS 9,8Kavram kanıtıEPSS %2dedebiz · dedecmsv623 Kas 2022
- CVE-2023-4323439İzleyin
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $ac
KritikCVSS 9,8İstismar yokEPSS %1dedebiz · dedebiz27 Eyl 2023
- CVE-2024-5277039İzleyin
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary c
KritikCVSS 9,8İstismar yokEPSS %1dedebiz · dedebiz20 Kas 2024
- CVE-2022-4412039İzleyin
dedecmdv6 6.1.9 is vulnerable to SQL Injection.
KritikCVSS 9,8İstismar yokEPSS %1dedebiz · dedecmsv623 Kas 2022
- CVE-2022-4319636İzleyin
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
KritikCVSS 9,1İstismar yokEPSS %1dedebiz · dedecmsv623 Kas 2022
- CVE-2024-5277136İzleyin
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
KritikCVSS 9,1İstismar yokEPSS %1dedebiz · dedebiz20 Kas 2024
- CVE-2023-526635İzleyin
DedeBIZ tags_main.php sql injection
YüksekCVSS 8,8İstismar yokEPSS %1dedebiz · dedebiz29 Eyl 2023
- CVE-2022-3621529İzleyin
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
YüksekCVSS 7,2İstismar yokEPSS %2dedebiz · dedecmsv617 Ağu 2022
- CVE-2023-718128İzleyin
Muyun DedeBIZ Add Attachment unrestricted upload
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz30 Ara 2023
- CVE-2024-5276928İzleyin
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz20 Kas 2024
- CVE-2023-675528İzleyin
DedeBIZ content_batchup_action.php sql injection
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz13 Ara 2023
- CVE-2023-383928İzleyin
DedeBIZ sys_sql_query.php sql injection
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz22 Tem 2023
- CVE-2024-055828İzleyin
DedeBIZ makehtml_freelist_action.php sql injection
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz15 Oca 2024
- CVE-2023-526828İzleyin
DedeBIZ makehtml_taglist_action.php sql injection
YüksekCVSS 7,2İstismar yokEPSS %1dedebiz · dedebiz29 Eyl 2023
- CVE-2024-4471624İzleyin
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
OrtaCVSS 6,1İstismar yokEPSS %0dedebiz · dedebiz29 Ağu 2024
- CVE-2024-4471724İzleyin
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
OrtaCVSS 6,1İstismar yokEPSS %0dedebiz · dedebiz29 Ağu 2024
- CVE-2024-790321İzleyin
DedeBIZ File Extension media_add.php unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1dedebiz · dedebiz18 Ağu 2024
- CVE-2024-790421İzleyin
DedeBIZ File Extension file_manage_control.php unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1dedebiz · dedebiz18 Ağu 2024
- CVE-2024-790521İzleyin
DedeBIZ archives_do.php AdminUpload unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1dedebiz · dedebiz18 Ağu 2024
- CVE-2024-790621İzleyin
DedeBIZ Attachment Settings select_images_post.php get_mime_type unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %0dedebiz · dedebiz18 Ağu 2024
- CVE-2024-055721İzleyin
DedeBIZ Website Copyright Setting cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %0dedebiz · dedebiz15 Oca 2024
- CVE-2023-4323221İzleyin
A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute a
OrtaCVSS 5,4İstismar yokEPSS %0dedebiz · dedebiz27 Eyl 2023
- CVE-2023-383719İzleyin
DedeBIZ sys_sql_query.php cross site scripting
OrtaCVSS 4,8İstismar yokEPSS %1dedebiz · dedebiz22 Tem 2023
- CVE-2023-417019İzleyin
DedeBIZ Article cross site scripting
OrtaCVSS 4,8İstismar yokEPSS %1dedebiz · dedebiz5 Ağu 2023