İçeriğe atla
Noroxi

getsymphony kayıtları

getsymphony üreticisine ait 18 yayımlanmış kayıt.

Tüm kayıtlar

18 kayıt
  • CVE-2017-7694
    36İzleyin

    Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attac

    YüksekCVSS 8,8İstismar yokEPSS %4

    getsymphony · symphony11 Nis 2017

  • CVE-2020-25912
    36İzleyin

    A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to a

    KritikCVSS 9,1İstismar yokEPSS %1

    getsymphony · symphony31 Eki 2021

  • CVE-2016-4309
    33İzleyin

    Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessi

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    getsymphony · symphony30 Haz 2016

  • CVE-2010-2143
    32İzleyin

    Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspe

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    getsymphony · symphony3 Haz 2010

  • CVE-2010-3458
    30İzleyin

    SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbit

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    getsymphony · symphony17 Eyl 2010

  • CVE-2013-2559
    27İzleyin

    SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort pa

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    getsymphony · symphony27 Mar 2014

  • CVE-2013-7346
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of adminis

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    getsymphony · symphony27 Mar 2014

  • CVE-2015-8766
    25İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attac

    OrtaCVSS 6,1İstismar yokEPSS %2

    getsymphony · symphony8 Oca 2016

  • CVE-2017-5542
    24İzleyin

    Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers t

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony20 Oca 2017

  • CVE-2015-8376
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony8 Oca 2016

  • CVE-2018-12043
    24İzleyin

    content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony7 Haz 2018

  • CVE-2017-8876
    24İzleyin

    Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony10 May 2017

  • CVE-2017-6067
    24İzleyin

    Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony26 Mar 2017

  • CVE-2020-15071
    24İzleyin

    content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.

    OrtaCVSS 6,1İstismar yokEPSS %1

    getsymphony · symphony11 Ağu 2020

  • CVE-2017-5541
    22İzleyin

    Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to renam

    OrtaCVSS 5,3İstismar yokEPSS %2

    getsymphony · symphony20 Oca 2017

  • CVE-2020-25343
    21İzleyin

    Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['bo

    OrtaCVSS 5,4İstismar yokEPSS %1

    getsymphony · symphony7 Eki 2020

  • CVE-2015-4661
    18İzleyin

    Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort p

    OrtaCVSS 4,3İstismar yokEPSS %2

    getsymphony · symphony18 Haz 2015

  • CVE-2010-3457
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or

    OrtaCVSS 4,3Kavram kanıtıEPSS %1

    getsymphony · symphony17 Eyl 2010