getsymphony kayıtları
getsymphony üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %5,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2017-7694İstismar yok | Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attacgetsymphony · symphony · CWE-94 | Yüksek8,8 | — | %4,4 | 11 Nis 2017 |
36İzleyin | CVE-2020-25912İstismar yok | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to agetsymphony · symphony · CWE-611 | Kritik9,1 | — | %1,4 | 31 Eki 2021 |
33İzleyin | CVE-2016-4309Kavram kanıtı | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessigetsymphony · symphony · CWE-362 | Yüksek7,5 | — | %10,2 | 30 Haz 2016 |
32İzleyin | CVE-2010-2143Kavram kanıtı | Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspegetsymphony · symphony · CWE-22 | Yüksek7,5 | — | %7,3 | 3 Haz 2010 |
30İzleyin | CVE-2010-3458Kavram kanıtı | SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitgetsymphony · symphony · CWE-89 | Yüksek7,5 | — | %1,0 | 17 Eyl 2010 |
27İzleyin | CVE-2013-2559Kavram kanıtı | SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort pagetsymphony · symphony · CWE-89 | Orta6,5 | — | %2,4 | 27 Mar 2014 |
27İzleyin | CVE-2013-7346Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of adminisgetsymphony · symphony · CWE-352 | Orta6,8 | — | %0,5 | 27 Mar 2014 |
25İzleyin | CVE-2015-8766İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attacgetsymphony · symphony · CWE-79 | Orta6,1 | — | %1,8 | 8 Oca 2016 |
24İzleyin | CVE-2017-5542İstismar yok | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers tgetsymphony · symphony · CWE-79 | Orta6,1 | — | %1,2 | 20 Oca 2017 |
24İzleyin | CVE-2015-8376İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via getsymphony · symphony · CWE-79 | Orta6,1 | — | %0,9 | 8 Oca 2016 |
24İzleyin | CVE-2018-12043İstismar yok | content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.getsymphony · symphony · CWE-79 | Orta6,1 | — | %0,8 | 7 Haz 2018 |
24İzleyin | CVE-2017-8876İstismar yok | Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.getsymphony · symphony · CWE-79 | Orta6,1 | — | %0,8 | 10 May 2017 |
24İzleyin | CVE-2017-6067İstismar yok | Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.getsymphony · symphony · CWE-79 | Orta6,1 | — | %0,8 | 26 Mar 2017 |
24İzleyin | CVE-2020-15071İstismar yok | content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.getsymphony · symphony · CWE-79 | Orta6,1 | — | %0,7 | 11 Ağu 2020 |
22İzleyin | CVE-2017-5541İstismar yok | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to renamgetsymphony · symphony · CWE-22 | Orta5,3 | — | %2,5 | 20 Oca 2017 |
21İzleyin | CVE-2020-25343İstismar yok | Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['bogetsymphony · symphony · CWE-79 | Orta5,4 | — | %0,7 | 7 Eki 2020 |
18İzleyin | CVE-2015-4661İstismar yok | Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort pgetsymphony · symphony · CWE-79 | Orta4,3 | — | %2,3 | 18 Haz 2015 |
17İzleyin | CVE-2010-3457Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script orgetsymphony · symphony · CWE-79 | Orta4,3 | — | %1,5 | 17 Eyl 2010 |
- CVE-2017-769436İzleyin
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attac
YüksekCVSS 8,8İstismar yokEPSS %4getsymphony · symphony11 Nis 2017
- CVE-2020-2591236İzleyin
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to a
KritikCVSS 9,1İstismar yokEPSS %1getsymphony · symphony31 Eki 2021
- CVE-2016-430933İzleyin
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessi
YüksekCVSS 7,5Kavram kanıtıEPSS %10getsymphony · symphony30 Haz 2016
- CVE-2010-214332İzleyin
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspe
YüksekCVSS 7,5Kavram kanıtıEPSS %7getsymphony · symphony3 Haz 2010
- CVE-2010-345830İzleyin
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbit
YüksekCVSS 7,5Kavram kanıtıEPSS %1getsymphony · symphony17 Eyl 2010
- CVE-2013-255927İzleyin
SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort pa
OrtaCVSS 6,5Kavram kanıtıEPSS %2getsymphony · symphony27 Mar 2014
- CVE-2013-734627İzleyin
Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of adminis
OrtaCVSS 6,8Kavram kanıtıEPSS %1getsymphony · symphony27 Mar 2014
- CVE-2015-876625İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attac
OrtaCVSS 6,1İstismar yokEPSS %2getsymphony · symphony8 Oca 2016
- CVE-2017-554224İzleyin
Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers t
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony20 Oca 2017
- CVE-2015-837624İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony8 Oca 2016
- CVE-2018-1204324İzleyin
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony7 Haz 2018
- CVE-2017-887624İzleyin
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony10 May 2017
- CVE-2017-606724İzleyin
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony26 Mar 2017
- CVE-2020-1507124İzleyin
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
OrtaCVSS 6,1İstismar yokEPSS %1getsymphony · symphony11 Ağu 2020
- CVE-2017-554122İzleyin
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to renam
OrtaCVSS 5,3İstismar yokEPSS %2getsymphony · symphony20 Oca 2017
- CVE-2020-2534321İzleyin
Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['bo
OrtaCVSS 5,4İstismar yokEPSS %1getsymphony · symphony7 Eki 2020
- CVE-2015-466118İzleyin
Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort p
OrtaCVSS 4,3İstismar yokEPSS %2getsymphony · symphony18 Haz 2015
- CVE-2010-345717İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %1getsymphony · symphony17 Eyl 2010