easyscripts kayıtları
easyscripts üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2001-1437İstismar yok | easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message easyscripts · easynews | Yüksek7,5 | — | %2,1 | 1 Ara 2001 |
30İzleyin | CVE-2008-1957Kavram kanıtı | SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parametereasyscripts · tr script news · CWE-89 | Yüksek7,5 | — | %1,2 | 25 Nis 2008 |
27İzleyin | CVE-2008-1958Kavram kanıtı | Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to exeasyscripts · tr script news · CWE-94 | Orta6,5 | — | %3,3 | 25 Nis 2008 |
21İzleyin | CVE-2001-1525Kavram kanıtı | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.daeasyscripts · easynews | Orta5,0 | — | %2,5 | 31 Ara 2001 |
17İzleyin | CVE-2001-1526İstismar yok | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject aeasyscripts · easynews | Orta4,3 | — | %1,0 | 31 Ara 2001 |
8İzleyin | CVE-2001-1527İstismar yok | easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and easyscripts · easynews | Düşük2,1 | — | %0,3 | 31 Ara 2001 |
- CVE-2001-143731İzleyin
easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message
YüksekCVSS 7,5İstismar yokEPSS %2easyscripts · easynews1 Ara 2001
- CVE-2008-195730İzleyin
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %1easyscripts · tr script news25 Nis 2008
- CVE-2008-195827İzleyin
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to ex
OrtaCVSS 6,5Kavram kanıtıEPSS %3easyscripts · tr script news25 Nis 2008
- CVE-2001-152521İzleyin
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.da
OrtaCVSS 5,0Kavram kanıtıEPSS %3easyscripts · easynews31 Ara 2001
- CVE-2001-152617İzleyin
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject a
OrtaCVSS 4,3İstismar yokEPSS %1easyscripts · easynews31 Ara 2001
- CVE-2001-15278İzleyin
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and
DüşükCVSS 2,1İstismar yokEPSS %0easyscripts · easynews31 Ara 2001