docebo kayıtları
docebo üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-31362İstismar yok | Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability.docebo · docebo · CWE-434 | Yüksek8,8 | — | %18,3 | 23 Haz 2022 |
39İzleyin | CVE-2022-31361İstismar yok | Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.docebo · docebo · CWE-89 | Kritik9,8 | — | %1,4 | 23 Haz 2022 |
31İzleyin | CVE-2008-7153Kavram kanıtı | SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote atdocebo · docebo · CWE-89 | Yüksek7,5 | — | %2,4 | 2 Eyl 2009 |
31İzleyin | CVE-2006-6963İstismar yok | Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in thedocebo · docebo | Yüksek7,5 | — | %1,8 | 29 Oca 2007 |
30İzleyin | CVE-2009-4742Kavram kanıtı | Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameterdocebo · docebo · CWE-89 | Yüksek7,5 | — | %0,6 | 26 Mar 2010 |
27İzleyin | CVE-2006-6957İstismar yok | PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows rdocebo · docebo · CWE-94 | Orta6,8 | — | %1,4 | 29 Oca 2007 |
24İzleyin | CVE-2011-5135Kavram kanıtı | Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and eardocebo · docebolms · CWE-89 | Orta6,0 | — | %0,9 | 30 Ağu 2012 |
23İzleyin | CVE-2006-2576Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Orta5,1 | — | %9,1 | 24 May 2006 |
21İzleyin | CVE-2008-7154Kavram kanıtı | Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) docebo · docebo · CWE-200 | Orta5,0 | — | %2,5 | 2 Eyl 2009 |
21İzleyin | CVE-2006-2577Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Orta5,1 | — | %2,4 | 24 May 2006 |
21İzleyin | CVE-2006-3107İstismar yok | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to docebo · docebo | Orta5,1 | — | %1,7 | 20 Haz 2006 |
20İzleyin | CVE-2011-3726İstismar yok | DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation docebo · docebolms · CWE-200 | Orta5,0 | — | %1,3 | 23 Eyl 2011 |
18İzleyin | CVE-2007-1240Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script docebo · docebo · CWE-79 | Orta4,3 | — | %3,2 | 3 Mar 2007 |
- CVE-2022-3136240Planlayın
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %18docebo · docebo23 Haz 2022
- CVE-2022-3136139İzleyin
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1docebo · docebo23 Haz 2022
- CVE-2008-715331İzleyin
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote at
YüksekCVSS 7,5Kavram kanıtıEPSS %2docebo · docebo2 Eyl 2009
- CVE-2006-696331İzleyin
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the
YüksekCVSS 7,5İstismar yokEPSS %2docebo · docebo29 Oca 2007
- CVE-2009-474230İzleyin
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %1docebo · docebo26 Mar 2010
- CVE-2006-695727İzleyin
PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows r
OrtaCVSS 6,8İstismar yokEPSS %1docebo · docebo29 Oca 2007
- CVE-2011-513524İzleyin
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in DoceboLMS 4.0.4 and ear
OrtaCVSS 6,0Kavram kanıtıEPSS %1docebo · docebolms30 Ağu 2012
- CVE-2006-257623İzleyin
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
OrtaCVSS 5,1Kavram kanıtıEPSS %9docebo · docebo24 May 2006
- CVE-2008-715421İzleyin
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2)
OrtaCVSS 5,0Kavram kanıtıEPSS %3docebo · docebo2 Eyl 2009
- CVE-2006-257721İzleyin
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
OrtaCVSS 5,1Kavram kanıtıEPSS %2docebo · docebo24 May 2006
- CVE-2006-310721İzleyin
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to
OrtaCVSS 5,1İstismar yokEPSS %2docebo · docebo20 Haz 2006
- CVE-2011-372620İzleyin
DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1docebo · docebolms23 Eyl 2011
- CVE-2007-124018İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3Kavram kanıtıEPSS %3docebo · docebo3 Mar 2007