İçeriğe atla
Noroxi

hisiphp kayıtları

hisiphp üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

6 kayıt
  • CVE-2024-33445
    39İzleyin

    An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter

    KritikCVSS 9,8İstismar yokEPSS %1

    hisiphp · hisiphp29 Nis 2024

  • CVE-2018-17826
    35İzleyin

    HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account.

    YüksekCVSS 8,8İstismar yokEPSS %0

    hisiphp · hisiphp1 Eki 2018

  • CVE-2020-28062
    29İzleyin

    An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath.

    YüksekCVSS 7,2İstismar yokEPSS %3

    hisiphp · hisiphp4 Nis 2022

  • CVE-2018-17827
    28İzleyin

    HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code.

    YüksekCVSS 7,2İstismar yokEPSS %1

    hisiphp · hisiphp1 Eki 2018

  • hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).

    OrtaCVSS 6,1İstismar yokEPSS %1

    hisiphp · hisiphp24 Tem 2019

  • CVE-2020-21130
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.

    OrtaCVSS 6,1İstismar yokEPSS %1

    hisiphp · hisiphp21 Haz 2021