froxlor kayıtları
froxlor üreticisine ait 48 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,1
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %91,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-863 Incorrect Authorization2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-840 Business Logic Errors2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
48 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2023-0315Silahlaştırılmış | Command Injection in froxlor/froxlorfroxlor · froxlor · CWE-77 | Yüksek8,8 | — | %97,7 | 15 Oca 2023 |
56Planlayın | CVE-2023-2034İstismar yok | Unrestricted Upload of File with Dangerous Type in froxlor/froxlorfroxlor · froxlor · CWE-434 | Yüksek8,8 | — | %71,4 | 13 Nis 2023 |
43Planlayın | CVE-2021-42325Kavram kanıtı | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.froxlor · froxlor · CWE-89 | Kritik9,8 | — | %11,8 | 12 Eki 2021 |
40Planlayın | CVE-2015-5959İstismar yok | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sfroxlor · froxlor · CWE-200 | Kritik9,8 | — | %3,1 | 6 Eyl 2017 |
40Planlayın | CVE-2016-5100İstismar yok | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passwfroxlor · froxlor · CWE-330 | Kritik9,8 | — | %1,9 | 13 Şub 2017 |
39İzleyin | CVE-2023-3173İstismar yok | Improper Restriction of Excessive Authentication Attempts in froxlor/froxlorfroxlor · froxlor · CWE-307 | Kritik9,8 | — | %1,1 | 8 Haz 2023 |
39İzleyin | CVE-2023-1307İstismar yok | Authentication Bypass by Primary Weakness in froxlor/froxlorfroxlor · froxlor · CWE-305 | Kritik9,8 | — | %1,1 | 9 Mar 2023 |
39İzleyin | CVE-2026-41228İstismar yok | Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Executionfroxlor · froxlor · CWE-98 | Kritik9,9 | — | %0,7 | 23 Nis 2026 |
38İzleyin | CVE-2024-34070Kavram kanıtı | Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromisefroxlor · froxlor · CWE-79 | Kritik9,6 | — | %1,0 | 14 May 2024 |
36İzleyin | CVE-2023-0877İstismar yok | Code Injection in froxlor/froxlorfroxlor · froxlor · CWE-94 | Yüksek8,8 | — | %3,9 | 16 Şub 2023 |
36İzleyin | CVE-2020-10235İstismar yok | An issue was discovered in Froxlor before 0.10.14.froxlor · froxlor · CWE-78 | Yüksek8,8 | — | %1,7 | 9 Mar 2020 |
36İzleyin | CVE-2026-26279İstismar yok | Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injectionfroxlor · froxlor · CWE-78 | Kritik9,1 | — | %1,1 | 3 Mar 2026 |
36İzleyin | CVE-2026-41229İstismar yok | Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)froxlor · froxlor · CWE-94 | Kritik9,1 | — | %0,7 | 23 Nis 2026 |
35İzleyin | CVE-2023-0671İstismar yok | Code Injection in froxlor/froxlorfroxlor · froxlor · CWE-94 | Yüksek8,8 | — | %1,1 | 3 Şub 2023 |
35İzleyin | CVE-2023-6069İstismar yok | Improper Link Resolution Before File Access in froxlor/froxlorfroxlor · froxlor · CWE-59 | Yüksek8,8 | — | %0,8 | 9 Kas 2023 |
35İzleyin | CVE-2023-1033İstismar yok | Cross-Site Request Forgery (CSRF) in froxlor/froxlorfroxlor · froxlor · CWE-352 | Yüksek8,8 | — | %0,3 | 24 Şub 2023 |
34İzleyin | CVE-2026-30932İstismar yok | Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APIfroxlor · froxlor · CWE-74 | Yüksek8,6 | — | %0,7 | 24 Mar 2026 |
34İzleyin | CVE-2026-41230İstismar yok | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()froxlor · froxlor · CWE-93 | Yüksek8,5 | — | %0,5 | 23 Nis 2026 |
31İzleyin | CVE-2025-29773İstismar yok | Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeoverfroxlor · froxlor · CWE-287 | Yüksek7,8 | — | %0,3 | 13 Mar 2025 |
30İzleyin | CVE-2018-12642İstismar yok | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.froxlor · froxlor · CWE-732 | Yüksek7,5 | — | %1,4 | 22 Haz 2018 |
30İzleyin | CVE-2023-50256İstismar yok | Froxlor username/surname AND company field Bypassfroxlor · froxlor · CWE-20 | Yüksek7,5 | — | %0,7 | 3 Oca 2024 |
30İzleyin | CVE-2023-2666İstismar yok | Allocation of Resources Without Limits or Throttling in froxlor/froxlorfroxlor · froxlor · CWE-770 | Yüksek7,5 | — | %0,7 | 11 May 2023 |
30İzleyin | CVE-2026-41231İstismar yok | Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cronfroxlor · froxlor · CWE-59 | Yüksek7,5 | — | %0,5 | 23 Nis 2026 |
30İzleyin | CVE-2023-0564İstismar yok | Weak Password Requirements in froxlor/froxlorfroxlor · froxlor · CWE-521 | Yüksek7,5 | — | %0,5 | 28 Oca 2023 |
29İzleyin | CVE-2018-1000527İstismar yok | Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclofroxlor · froxlor · CWE-502 | Yüksek7,2 | — | %2,6 | 26 Haz 2018 |
- CVE-2023-031564Bu hafta
Command Injection in froxlor/froxlor
YüksekCVSS 8,8SilahlaştırılmışEPSS %98froxlor · froxlor15 Oca 2023
- CVE-2023-203456Planlayın
Unrestricted Upload of File with Dangerous Type in froxlor/froxlor
YüksekCVSS 8,8İstismar yokEPSS %71froxlor · froxlor13 Nis 2023
- CVE-2021-4232543Planlayın
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
KritikCVSS 9,8Kavram kanıtıEPSS %12froxlor · froxlor12 Eki 2021
- CVE-2015-595940Planlayın
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/s
KritikCVSS 9,8İstismar yokEPSS %3froxlor · froxlor6 Eyl 2017
- CVE-2016-510040Planlayın
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw
KritikCVSS 9,8İstismar yokEPSS %2froxlor · froxlor13 Şub 2017
- CVE-2023-317339İzleyin
Improper Restriction of Excessive Authentication Attempts in froxlor/froxlor
KritikCVSS 9,8İstismar yokEPSS %1froxlor · froxlor8 Haz 2023
- CVE-2023-130739İzleyin
Authentication Bypass by Primary Weakness in froxlor/froxlor
KritikCVSS 9,8İstismar yokEPSS %1froxlor · froxlor9 Mar 2023
- CVE-2026-4122839İzleyin
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
KritikCVSS 9,9İstismar yokEPSS %1froxlor · froxlor23 Nis 2026
- CVE-2024-3407038İzleyin
Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise
KritikCVSS 9,6Kavram kanıtıEPSS %1froxlor · froxlor14 May 2024
- CVE-2023-087736İzleyin
Code Injection in froxlor/froxlor
YüksekCVSS 8,8İstismar yokEPSS %4froxlor · froxlor16 Şub 2023
- CVE-2020-1023536İzleyin
An issue was discovered in Froxlor before 0.10.14.
YüksekCVSS 8,8İstismar yokEPSS %2froxlor · froxlor9 Mar 2020
- CVE-2026-2627936İzleyin
Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
KritikCVSS 9,1İstismar yokEPSS %1froxlor · froxlor3 Mar 2026
- CVE-2026-4122936İzleyin
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
KritikCVSS 9,1İstismar yokEPSS %1froxlor · froxlor23 Nis 2026
- CVE-2023-067135İzleyin
Code Injection in froxlor/froxlor
YüksekCVSS 8,8İstismar yokEPSS %1froxlor · froxlor3 Şub 2023
- CVE-2023-606935İzleyin
Improper Link Resolution Before File Access in froxlor/froxlor
YüksekCVSS 8,8İstismar yokEPSS %1froxlor · froxlor9 Kas 2023
- CVE-2023-103335İzleyin
Cross-Site Request Forgery (CSRF) in froxlor/froxlor
YüksekCVSS 8,8İstismar yokEPSS %0froxlor · froxlor24 Şub 2023
- CVE-2026-3093234İzleyin
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
YüksekCVSS 8,6İstismar yokEPSS %1froxlor · froxlor24 Mar 2026
- CVE-2026-4123034İzleyin
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
YüksekCVSS 8,5İstismar yokEPSS %1froxlor · froxlor23 Nis 2026
- CVE-2025-2977331İzleyin
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
YüksekCVSS 7,8İstismar yokEPSS %0froxlor · froxlor13 Mar 2025
- CVE-2018-1264230İzleyin
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
YüksekCVSS 7,5İstismar yokEPSS %1froxlor · froxlor22 Haz 2018
- CVE-2023-5025630İzleyin
Froxlor username/surname AND company field Bypass
YüksekCVSS 7,5İstismar yokEPSS %1froxlor · froxlor3 Oca 2024
- CVE-2023-266630İzleyin
Allocation of Resources Without Limits or Throttling in froxlor/froxlor
YüksekCVSS 7,5İstismar yokEPSS %1froxlor · froxlor11 May 2023
- CVE-2026-4123130İzleyin
Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
YüksekCVSS 7,5İstismar yokEPSS %1froxlor · froxlor23 Nis 2026
- CVE-2023-056430İzleyin
Weak Password Requirements in froxlor/froxlor
YüksekCVSS 7,5İstismar yokEPSS %0froxlor · froxlor28 Oca 2023
- CVE-2018-100052729İzleyin
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclo
YüksekCVSS 7,2İstismar yokEPSS %3froxlor · froxlor26 Haz 2018