I-Doit kayıtları
i-doit üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-37756Kavram kanıtı | I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation.i-doit · i-doit · CWE-521 | Kritik9,8 | — | %1,4 | 14 Eyl 2023 |
39İzleyin | CVE-2023-37755Kavram kanıtı | i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warningi-doit · i-doit · CWE-798 | Kritik9,8 | — | %1,4 | 14 Eyl 2023 |
39İzleyin | CVE-2019-1010248İstismar yok | Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection.i-doit · i-doit · CWE-89 | Kritik9,8 | — | %1,4 | 18 Tem 2019 |
35İzleyin | CVE-2020-13826İstismar yok | A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands viai-doit · i-doit · CWE-1236 | Yüksek8,8 | — | %1,5 | 19 Ağu 2020 |
35İzleyin | CVE-2019-25581İstismar yok | i-doit CMDB 1.12 SQL Injection via objGroupID Parameteri-doit · i-doit · CWE-89 | Yüksek8,8 | — | %0,4 | 21 Mar 2026 |
31İzleyin | CVE-2018-20159Kavram kanıtı | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled.i-doit · i-doit · CWE-20 | Yüksek7,2 | — | %9,9 | 15 Ara 2018 |
30İzleyin | CVE-2014-1597Kavram kanıtı | SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execui-doit · i-doit · CWE-89 | Yüksek7,5 | — | %1,4 | 27 Şub 2014 |
30İzleyin | CVE-2024-8749İstismar yok | SQL Injection vulnerability in Idoit proi-doit · i-doit · CWE-89 | Yüksek7,5 | — | %0,4 | 12 Eyl 2024 |
28İzleyin | CVE-2019-25582İstismar yok | i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameteri-doit · i-doit · CWE-434 | Yüksek7,1 | — | %0,4 | 21 Mar 2026 |
26İzleyin | CVE-2023-37739Kavram kanıtı | i-doit Pro v25 and below was discovered to be vulnerable to path traversal.i-doit · i-doit · CWE-22 | Orta6,5 | — | %1,3 | 14 Eyl 2023 |
25İzleyin | CVE-2019-6965Kavram kanıtı | An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.i-doit · i-doit · CWE-79 | Orta6,1 | — | %2,5 | 18 Haz 2019 |
24İzleyin | CVE-2020-13825İstismar yok | A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode,i-doit · i-doit · CWE-79 | Orta6,1 | — | %0,8 | 19 Ağu 2020 |
24İzleyin | CVE-2024-8750İstismar yok | Cross-site Scripting vulnerability in Idoit proi-doit · i-doit · CWE-79 | Orta6,1 | — | %0,2 | 12 Eyl 2024 |
21İzleyin | CVE-2021-3151İstismar yok | i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbiti-doit · i-doit · CWE-79 | Orta5,4 | — | %1,2 | 27 Şub 2021 |
21İzleyin | CVE-2023-34830Kavram kanıtı | i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.i-doit · i-doit · CWE-79 | Orta5,4 | — | %0,7 | 27 Haz 2023 |
21İzleyin | CVE-2023-46003Kavram kanıtı | I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.i-doit · i-doit · CWE-79 | Orta5,4 | — | %0,5 | 20 Eki 2023 |
18İzleyin | CVE-2014-1237İstismar yok | Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary web script or HTML i-doit · i-doit · CWE-79 | Orta4,3 | — | %1,7 | 11 Şub 2014 |
17İzleyin | CVE-2013-1413İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when ti-doit · i-doit · CWE-79 | Orta4,3 | — | %1,2 | 11 Şub 2014 |
17İzleyin | CVE-2014-2231İstismar yok | Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web scrii-doit · i-doit · CWE-79 | Orta4,3 | — | %0,9 | 27 Şub 2014 |
- CVE-2023-3775639İzleyin
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation.
KritikCVSS 9,8Kavram kanıtıEPSS %1i-doit · i-doit14 Eyl 2023
- CVE-2023-3775539İzleyin
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning
KritikCVSS 9,8Kavram kanıtıEPSS %1i-doit · i-doit14 Eyl 2023
- CVE-2019-101024839İzleyin
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection.
KritikCVSS 9,8İstismar yokEPSS %1i-doit · i-doit18 Tem 2019
- CVE-2020-1382635İzleyin
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via
YüksekCVSS 8,8İstismar yokEPSS %1i-doit · i-doit19 Ağu 2020
- CVE-2019-2558135İzleyin
i-doit CMDB 1.12 SQL Injection via objGroupID Parameter
YüksekCVSS 8,8İstismar yokEPSS %0i-doit · i-doit21 Mar 2026
- CVE-2018-2015931İzleyin
i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled.
YüksekCVSS 7,2Kavram kanıtıEPSS %10i-doit · i-doit15 Ara 2018
- CVE-2014-159730İzleyin
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execu
YüksekCVSS 7,5Kavram kanıtıEPSS %1i-doit · i-doit27 Şub 2014
- CVE-2024-874930İzleyin
SQL Injection vulnerability in Idoit pro
YüksekCVSS 7,5İstismar yokEPSS %0i-doit · i-doit12 Eyl 2024
- CVE-2019-2558228İzleyin
i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameter
YüksekCVSS 7,1İstismar yokEPSS %0i-doit · i-doit21 Mar 2026
- CVE-2023-3773926İzleyin
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
OrtaCVSS 6,5Kavram kanıtıEPSS %1i-doit · i-doit14 Eyl 2023
- CVE-2019-696525İzleyin
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %3i-doit · i-doit18 Haz 2019
- CVE-2020-1382524İzleyin
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode,
OrtaCVSS 6,1İstismar yokEPSS %1i-doit · i-doit19 Ağu 2020
- CVE-2024-875024İzleyin
Cross-site Scripting vulnerability in Idoit pro
OrtaCVSS 6,1İstismar yokEPSS %0i-doit · i-doit12 Eyl 2024
- CVE-2021-315121İzleyin
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbit
OrtaCVSS 5,4İstismar yokEPSS %1i-doit · i-doit27 Şub 2021
- CVE-2023-3483021İzleyin
i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.
OrtaCVSS 5,4Kavram kanıtıEPSS %1i-doit · i-doit27 Haz 2023
- CVE-2023-4600321İzleyin
I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
OrtaCVSS 5,4Kavram kanıtıEPSS %1i-doit · i-doit20 Eki 2023
- CVE-2014-123718İzleyin
Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3İstismar yokEPSS %2i-doit · i-doit11 Şub 2014
- CVE-2013-141317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when t
OrtaCVSS 4,3İstismar yokEPSS %1i-doit · i-doit11 Şub 2014
- CVE-2014-223117İzleyin
Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to inject arbitrary web scri
OrtaCVSS 4,3İstismar yokEPSS %1i-doit · i-doit27 Şub 2014