doorgets kayıtları
doorgets üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-21 DEPRECATED: Pathname Traversal and Equivalence Errors1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-11616İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php.doorgets · doorgets cms | Kritik9,8 | — | %2,4 | 30 Nis 2019 |
40Planlayın | CVE-2019-11618İstismar yok | doorGets 7.0 has a default administrator credential vulnerability.doorgets · doorgets cms · CWE-1188 | Kritik9,8 | — | %2,3 | 30 Nis 2019 |
35İzleyin | CVE-2019-11615İstismar yok | /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability.doorgets · doorgets cms · CWE-434 | Yüksek8,8 | — | %1,5 | 30 Nis 2019 |
35İzleyin | CVE-2019-11617İstismar yok | doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php.doorgets · doorgets cms · CWE-352 | Yüksek8,8 | — | %0,8 | 30 Nis 2019 |
35İzleyin | CVE-2018-11126İstismar yok | dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.doorgets · doorgets · CWE-352 | Yüksek8,8 | — | %0,6 | 15 May 2018 |
33İzleyin | CVE-2019-11608İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php.doorgets · doorgets cms · CWE-22 | Yüksek8,2 | — | %4,1 | 30 Nis 2019 |
33İzleyin | CVE-2019-11609İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php.doorgets · doorgets cms · CWE-22 | Yüksek8,2 | — | %4,0 | 30 Nis 2019 |
31İzleyin | CVE-2019-11606İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php.doorgets · doorgets cms · CWE-22 | Yüksek7,5 | — | %3,9 | 30 Nis 2019 |
31İzleyin | CVE-2019-11607İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php.doorgets · doorgets cms · CWE-22 | Yüksek7,5 | — | %3,9 | 30 Nis 2019 |
31İzleyin | CVE-2019-11610İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php.doorgets · doorgets cms · CWE-22 | Yüksek7,5 | — | %3,9 | 30 Nis 2019 |
31İzleyin | CVE-2019-11611İstismar yok | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php.doorgets · doorgets cms · CWE-22 | Yüksek7,5 | — | %3,9 | 30 Nis 2019 |
31İzleyin | CVE-2019-11612İstismar yok | doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php.doorgets · doorgets cms · CWE-22 | Yüksek7,5 | — | %2,7 | 30 Nis 2019 |
31İzleyin | CVE-2018-20064İstismar yok | doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&actdoorgets · doorgets · CWE-22 | Yüksek7,5 | — | %2,7 | 11 Ara 2018 |
30İzleyin | CVE-2019-11614İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php.doorgets · doorgets cms · CWE-89 | Yüksek7,5 | — | %1,5 | 30 Nis 2019 |
27İzleyin | CVE-2014-1459Kavram kanıtı | SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbidoorgets · doorgets cms · CWE-89 | Orta6,5 | — | %2,3 | 11 Şub 2014 |
26İzleyin | CVE-2019-11613İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php.doorgets · doorgets cms · CWE-89 | Orta6,5 | — | %1,2 | 30 Nis 2019 |
21İzleyin | CVE-2019-11626İstismar yok | routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c doorgets · doorgets cms · CWE-21 | Orta5,3 | — | %1,3 | 30 Nis 2019 |
19İzleyin | CVE-2019-11624İstismar yok | doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php.doorgets · doorgets cms · CWE-22 | Orta4,9 | — | %1,6 | 30 Nis 2019 |
19İzleyin | CVE-2019-11621İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
19İzleyin | CVE-2019-11622İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
19İzleyin | CVE-2019-11620İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
19İzleyin | CVE-2019-11625İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
19İzleyin | CVE-2019-11619İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
19İzleyin | CVE-2019-11623İstismar yok | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb.doorgets · doorgets cms · CWE-89 | Orta4,9 | — | %1,2 | 30 Nis 2019 |
- CVE-2019-1161640Planlayın
doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php.
KritikCVSS 9,8İstismar yokEPSS %2doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161840Planlayın
doorGets 7.0 has a default administrator credential vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161535İzleyin
/fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161735İzleyin
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php.
YüksekCVSS 8,8İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2018-1112635İzleyin
dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.
YüksekCVSS 8,8İstismar yokEPSS %1doorgets · doorgets15 May 2018
- CVE-2019-1160833İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php.
YüksekCVSS 8,2İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1160933İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php.
YüksekCVSS 8,2İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1160631İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php.
YüksekCVSS 7,5İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1160731İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php.
YüksekCVSS 7,5İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161031İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php.
YüksekCVSS 7,5İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161131İzleyin
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php.
YüksekCVSS 7,5İstismar yokEPSS %4doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161231İzleyin
doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php.
YüksekCVSS 7,5İstismar yokEPSS %3doorgets · doorgets cms30 Nis 2019
- CVE-2018-2006431İzleyin
doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&act
YüksekCVSS 7,5İstismar yokEPSS %3doorgets · doorgets11 Ara 2018
- CVE-2019-1161430İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php.
YüksekCVSS 7,5İstismar yokEPSS %2doorgets · doorgets cms30 Nis 2019
- CVE-2014-145927İzleyin
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbi
OrtaCVSS 6,5Kavram kanıtıEPSS %2doorgets · doorgets cms11 Şub 2014
- CVE-2019-1161326İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php.
OrtaCVSS 6,5İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162621İzleyin
routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c
OrtaCVSS 5,3İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162419İzleyin
doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php.
OrtaCVSS 4,9İstismar yokEPSS %2doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162119İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162219İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162019İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162519İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1161919İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019
- CVE-2019-1162319İzleyin
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb.
OrtaCVSS 4,9İstismar yokEPSS %1doorgets · doorgets cms30 Nis 2019