flyspray kayıtları
flyspray üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %10
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
27İzleyin | CVE-2007-1788İstismar yok | Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted poflyspray · flyspray | Orta6,8 | — | %1,3 | 31 Mar 2007 |
27İzleyin | CVE-2007-1789İstismar yok | Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.flyspray · flyspray | Orta6,8 | — | %1,2 | 31 Mar 2007 |
24İzleyin | CVE-2012-1058Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requeflyspray · flyspray · CWE-352 | Orta6,0 | — | %0,9 | 13 Şub 2012 |
22İzleyin | CVE-2006-0714Kavram kanıtı | Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbiflyspray · flyspray | Orta5,0 | — | %7,8 | 15 Şub 2006 |
21İzleyin | CVE-2017-15214İstismar yok | Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privilegflyspray · flyspray · CWE-79 | Orta5,4 | — | %0,9 | 10 Eki 2017 |
21İzleyin | CVE-2017-15213İstismar yok | Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via flyspray · flyspray · CWE-79 | Orta5,4 | — | %0,8 | 10 Eki 2017 |
20İzleyin | CVE-2008-1166İstismar yok | Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to flyspray · flyspray · CWE-200 | Orta5,0 | — | %1,2 | 5 Mar 2008 |
18İzleyin | CVE-2005-3334Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary weflyspray · flyspray | Orta4,3 | — | %4,6 | 27 Eki 2005 |
17İzleyin | CVE-2007-6461İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrarflyspray · flyspray · CWE-79 | Orta4,3 | — | %1,1 | 19 Ara 2007 |
17İzleyin | CVE-2008-1165İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script flyspray · flyspray · CWE-79 | Orta4,3 | — | %1,0 | 5 Mar 2008 |
- CVE-2007-178827İzleyin
Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted po
OrtaCVSS 6,8İstismar yokEPSS %1flyspray · flyspray31 Mar 2007
- CVE-2007-178927İzleyin
Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.
OrtaCVSS 6,8İstismar yokEPSS %1flyspray · flyspray31 Mar 2007
- CVE-2012-105824İzleyin
Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for reque
OrtaCVSS 6,0Kavram kanıtıEPSS %1flyspray · flyspray13 Şub 2012
- CVE-2006-071422İzleyin
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbi
OrtaCVSS 5,0Kavram kanıtıEPSS %8flyspray · flyspray15 Şub 2006
- CVE-2017-1521421İzleyin
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileg
OrtaCVSS 5,4İstismar yokEPSS %1flyspray · flyspray10 Eki 2017
- CVE-2017-1521321İzleyin
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via
OrtaCVSS 5,4İstismar yokEPSS %1flyspray · flyspray10 Eki 2017
- CVE-2008-116620İzleyin
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to
OrtaCVSS 5,0İstismar yokEPSS %1flyspray · flyspray5 Mar 2008
- CVE-2005-333418İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary we
OrtaCVSS 4,3Kavram kanıtıEPSS %5flyspray · flyspray27 Eki 2005
- CVE-2007-646117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrar
OrtaCVSS 4,3İstismar yokEPSS %1flyspray · flyspray19 Ara 2007
- CVE-2008-116517İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1flyspray · flyspray5 Mar 2008