dynpg kayıtları
dynpg üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2010-4400Kavram kanıtı | SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_Udynpg · dynpg · CWE-89 | Yüksek7,5 | — | %2,2 | 6 Ara 2010 |
23İzleyin | CVE-2010-1299Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_dynpg · dynpg · CWE-94 | Orta5,1 | — | %10,7 | 7 Nis 2010 |
22İzleyin | CVE-2010-4401Kavram kanıtı | languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installdynpg · dynpg · CWE-200 | Orta5,0 | — | %5,6 | 6 Ara 2010 |
21İzleyin | CVE-2020-27406İstismar yok | Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.dynpg · dynpg · CWE-79 | Orta5,4 | — | %0,8 | 2 Kas 2021 |
19İzleyin | CVE-2010-4399Kavram kanıtı | Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackdynpg · dynpg · CWE-22 | Orta4,3 | — | %5,6 | 6 Ara 2010 |
19İzleyin | CVE-2021-27531İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
19İzleyin | CVE-2021-27527İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
19İzleyin | CVE-2021-27528İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
19İzleyin | CVE-2021-27529İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
19İzleyin | CVE-2021-27530İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
19İzleyin | CVE-2021-27526İstismar yok | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.dynpg · dynpg · CWE-79 | Orta4,8 | — | %0,8 | 23 Mar 2021 |
- CVE-2010-440031İzleyin
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_U
YüksekCVSS 7,5Kavram kanıtıEPSS %2dynpg · dynpg6 Ara 2010
- CVE-2010-129923İzleyin
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_
OrtaCVSS 5,1Kavram kanıtıEPSS %11dynpg · dynpg7 Nis 2010
- CVE-2010-440122İzleyin
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the install
OrtaCVSS 5,0Kavram kanıtıEPSS %6dynpg · dynpg6 Ara 2010
- CVE-2020-2740621İzleyin
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.
OrtaCVSS 5,4İstismar yokEPSS %1dynpg · dynpg2 Kas 2021
- CVE-2010-439919İzleyin
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attack
OrtaCVSS 4,3Kavram kanıtıEPSS %6dynpg · dynpg6 Ara 2010
- CVE-2021-2753119İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021
- CVE-2021-2752719İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021
- CVE-2021-2752819İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021
- CVE-2021-2752919İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021
- CVE-2021-2753019İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021
- CVE-2021-2752619İzleyin
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.
OrtaCVSS 4,8İstismar yokEPSS %1dynpg · dynpg23 Mar 2021