ez kayıtları
ez üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %13
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-19 Data Processing Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-4493İstismar yok | eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unez · ez publish | Kritik10,0 | — | %1,8 | 22 Ağu 2007 |
40Planlayın | CVE-2020-10806İstismar yok | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.ez · ez publish-kernel · CWE-434 | Kritik9,8 | — | %2,3 | 22 Mar 2020 |
37İzleyin | CVE-2005-4853İstismar yok | The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 2005081ez · ez publish · CWE-264 | Kritik9,4 | — | %1,5 | 31 Ara 2005 |
31İzleyin | CVE-2008-6844Kavram kanıtı | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows ez · ez publish · CWE-264 | Yüksek7,5 | — | %3,0 | 2 Tem 2009 |
31İzleyin | CVE-2012-1565İstismar yok | Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direez · ez publish | Yüksek7,5 | — | %2,0 | 6 Eki 2012 |
30İzleyin | CVE-2010-2672İstismar yok | Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1ez · ez publish · CWE-89 | Yüksek7,5 | — | %1,3 | 8 Tem 2010 |
28İzleyin | CVE-2003-0310Kavram kanıtı | Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.ez · ez publish · CWE-79 | Orta6,8 | — | %3,2 | 16 Haz 2003 |
27İzleyin | CVE-2012-4053İstismar yok | Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the autez · ez publish · CWE-352 | Orta6,8 | — | %0,6 | 25 Tem 2012 |
24İzleyin | CVE-2019-12139İstismar yok | An XSS issue was discovered in the Admin UI in eZ Platform 2.x.ez · ezplatform-admin-ui · CWE-79 | Orta6,1 | — | %0,8 | 16 May 2019 |
24İzleyin | CVE-2017-1000431İstismar yok | eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk ez · ez publish · CWE-79 | Orta6,1 | — | %0,7 | 2 Oca 2018 |
21İzleyin | CVE-2007-4494İstismar yok | The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attaez · ez publish | Orta5,0 | — | %1,7 | 22 Ağu 2007 |
20İzleyin | CVE-2005-4852İstismar yok | The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI toez · ez publish · CWE-264 | Orta5,0 | — | %1,1 | 31 Ara 2005 |
20İzleyin | CVE-2005-4854İstismar yok | eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticez · ez publish · CWE-264 | Orta5,0 | — | %1,1 | 31 Ara 2005 |
20İzleyin | CVE-2005-4856İstismar yok | The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle autez · ez publish · CWE-19 | Orta5,0 | — | %1,1 | 31 Ara 2005 |
20İzleyin | CVE-2005-4850İstismar yok | eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers ez · ez publish · CWE-264 | Orta5,0 | — | %1,0 | 31 Ara 2005 |
17İzleyin | CVE-2006-0938İstismar yok | Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via ez · ez publish · CWE-79 | Orta4,3 | — | %1,3 | 28 Şub 2006 |
17İzleyin | CVE-2010-2671İstismar yok | Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitraryez · ez publish · CWE-79 | Orta4,3 | — | %1,3 | 8 Tem 2010 |
16İzleyin | CVE-2006-7219İstismar yok | eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users toez · ez publish · CWE-264 | Orta4,0 | — | %1,0 | 6 Tem 2007 |
16İzleyin | CVE-2006-7218İstismar yok | eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allowez · ez publish · CWE-264 | Orta4,0 | — | %1,0 | 6 Tem 2007 |
16İzleyin | CVE-2005-4857İstismar yok | eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denialez · ez publish · CWE-399 | Orta4,0 | — | %0,9 | 31 Ara 2005 |
16İzleyin | CVE-2005-4851İstismar yok | eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypasez · ez publish · CWE-287 | Orta4,0 | — | %0,9 | 31 Ara 2005 |
14İzleyin | CVE-2005-4855İstismar yok | Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does nez · ez publish · CWE-264 | Düşük3,5 | — | %0,7 | 31 Ara 2005 |
11İzleyin | CVE-2012-1597Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 aez · ezjscore · CWE-79 | Düşük2,6 | — | %4,1 | 16 Ağu 2012 |
- CVE-2007-449341Planlayın
eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has un
KritikCVSS 10,0İstismar yokEPSS %2ez · ez publish22 Ağu 2007
- CVE-2020-1080640Planlayın
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.
KritikCVSS 9,8İstismar yokEPSS %2ez · ez publish-kernel22 Mar 2020
- CVE-2005-485337İzleyin
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 2005081
KritikCVSS 9,4İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2008-684431İzleyin
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows
YüksekCVSS 7,5Kavram kanıtıEPSS %3ez · ez publish2 Tem 2009
- CVE-2012-156531İzleyin
Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure dire
YüksekCVSS 7,5İstismar yokEPSS %2ez · ez publish6 Eki 2012
- CVE-2010-267230İzleyin
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1
YüksekCVSS 7,5İstismar yokEPSS %1ez · ez publish8 Tem 2010
- CVE-2003-031028İzleyin
Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.
OrtaCVSS 6,8Kavram kanıtıEPSS %3ez · ez publish16 Haz 2003
- CVE-2012-405327İzleyin
Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the aut
OrtaCVSS 6,8İstismar yokEPSS %1ez · ez publish25 Tem 2012
- CVE-2019-1213924İzleyin
An XSS issue was discovered in the Admin UI in eZ Platform 2.x.
OrtaCVSS 6,1İstismar yokEPSS %1ez · ezplatform-admin-ui16 May 2019
- CVE-2017-100043124İzleyin
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk
OrtaCVSS 6,1İstismar yokEPSS %1ez · ez publish2 Oca 2018
- CVE-2007-449421İzleyin
The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote atta
OrtaCVSS 5,0İstismar yokEPSS %2ez · ez publish22 Ağu 2007
- CVE-2005-485220İzleyin
The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to
OrtaCVSS 5,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2005-485420İzleyin
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authentic
OrtaCVSS 5,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2005-485620İzleyin
The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle aut
OrtaCVSS 5,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2005-485020İzleyin
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers
OrtaCVSS 5,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2006-093817İzleyin
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %1ez · ez publish28 Şub 2006
- CVE-2010-267117İzleyin
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary
OrtaCVSS 4,3İstismar yokEPSS %1ez · ez publish8 Tem 2010
- CVE-2006-721916İzleyin
eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to
OrtaCVSS 4,0İstismar yokEPSS %1ez · ez publish6 Tem 2007
- CVE-2006-721816İzleyin
eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allow
OrtaCVSS 4,0İstismar yokEPSS %1ez · ez publish6 Tem 2007
- CVE-2005-485716İzleyin
eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial
OrtaCVSS 4,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2005-485116İzleyin
eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypas
OrtaCVSS 4,0İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2005-485514İzleyin
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does n
DüşükCVSS 3,5İstismar yokEPSS %1ez · ez publish31 Ara 2005
- CVE-2012-159711İzleyin
Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 a
DüşükCVSS 2,6Kavram kanıtıEPSS %4ez · ezjscore16 Ağu 2012