duraspace kayıtları
duraspace üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-863 Incorrect Authorization1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2019-6986İstismar yok | SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular exprduraspace · vitro · CWE-77 | Yüksek7,5 | — | %3,0 | 28 Oca 2019 |
31İzleyin | CVE-2016-10726Kavram kanıtı | The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack withduraspace · dspace · CWE-22 | Yüksek7,5 | — | %2,9 | 10 Tem 2018 |
29İzleyin | CVE-2021-41189İstismar yok | Communities and collections administrators can escalate their privilege up to system administratorduraspace · dspace · CWE-863 | Yüksek7,2 | — | %2,1 | 29 Eki 2021 |
28İzleyin | CVE-2022-31195Kavram kanıtı | Path traversal vulnerability in Simple Archive Format package import in DSpaceduraspace · dspace · CWE-22 | Yüksek7,2 | — | %1,4 | 1 Ağu 2022 |
28İzleyin | CVE-2022-31194Kavram kanıtı | Path traversal vulnerabilities in DSpace JSPUI submission uploadduraspace · dspace · CWE-22 | Yüksek7,2 | — | %1,1 | 1 Ağu 2022 |
24İzleyin | CVE-2022-31191İstismar yok | Cross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete toolsduraspace · dspace · CWE-79 | Orta6,1 | — | %0,8 | 1 Ağu 2022 |
24İzleyin | CVE-2022-31192Kavram kanıtı | Cross Site Scripting possible in DSpace JSPUI "Request a Copy" featureduraspace · dspace · CWE-79 | Orta6,1 | — | %0,8 | 1 Ağu 2022 |
24İzleyin | CVE-2022-31193İstismar yok | URL Redirection to Untrusted Site in Dspace JSPUIduraspace · dspace · CWE-601 | Orta6,1 | — | %0,7 | 1 Ağu 2022 |
21İzleyin | CVE-2022-31190İstismar yok | Metadata of withdrawn Items is exposed to anonymous users in DSpace XMLUIduraspace · dspace · CWE-200 | Orta5,3 | — | %0,9 | 1 Ağu 2022 |
21İzleyin | CVE-2022-31189İstismar yok | "Internal System Error" page in DSpace JSPUI prints exceptions and stack traces without sanitizationduraspace · dspace · CWE-209 | Orta5,3 | — | %0,7 | 1 Ağu 2022 |
- CVE-2019-698631İzleyin
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expr
YüksekCVSS 7,5İstismar yokEPSS %3duraspace · vitro28 Oca 2019
- CVE-2016-1072631İzleyin
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with
YüksekCVSS 7,5Kavram kanıtıEPSS %3duraspace · dspace10 Tem 2018
- CVE-2021-4118929İzleyin
Communities and collections administrators can escalate their privilege up to system administrator
YüksekCVSS 7,2İstismar yokEPSS %2duraspace · dspace29 Eki 2021
- CVE-2022-3119528İzleyin
Path traversal vulnerability in Simple Archive Format package import in DSpace
YüksekCVSS 7,2Kavram kanıtıEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3119428İzleyin
Path traversal vulnerabilities in DSpace JSPUI submission upload
YüksekCVSS 7,2Kavram kanıtıEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3119124İzleyin
Cross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete tools
OrtaCVSS 6,1İstismar yokEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3119224İzleyin
Cross Site Scripting possible in DSpace JSPUI "Request a Copy" feature
OrtaCVSS 6,1Kavram kanıtıEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3119324İzleyin
URL Redirection to Untrusted Site in Dspace JSPUI
OrtaCVSS 6,1İstismar yokEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3119021İzleyin
Metadata of withdrawn Items is exposed to anonymous users in DSpace XMLUI
OrtaCVSS 5,3İstismar yokEPSS %1duraspace · dspace1 Ağu 2022
- CVE-2022-3118921İzleyin
"Internal System Error" page in DSpace JSPUI prints exceptions and stack traces without sanitization
OrtaCVSS 5,3İstismar yokEPSS %1duraspace · dspace1 Ağu 2022