infinitewp kayıtları
infinitewp üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-28642İstismar yok | In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attainfinitewp · infinitewp · CWE-338 | Kritik9,8 | — | %2,6 | 15 Kas 2020 |
31İzleyin | CVE-2014-9521İstismar yok | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is seinfinitewp · infinitewp · CWE-94 | Yüksek7,5 | — | %2,3 | 5 Oca 2015 |
30İzleyin | CVE-2014-9519İstismar yok | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands viinfinitewp · infinitewp · CWE-89 | Yüksek7,5 | — | %1,2 | 5 Oca 2015 |
30İzleyin | CVE-2014-9520İstismar yok | SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands infinitewp · infinitewp · CWE-89 | Yüksek7,5 | — | %1,2 | 5 Oca 2015 |
- CVE-2020-2864240Planlayın
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote atta
KritikCVSS 9,8İstismar yokEPSS %3infinitewp · infinitewp15 Kas 2020
- CVE-2014-952131İzleyin
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is se
YüksekCVSS 7,5İstismar yokEPSS %2infinitewp · infinitewp5 Oca 2015
- CVE-2014-951930İzleyin
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %1infinitewp · infinitewp5 Oca 2015
- CVE-2014-952030İzleyin
SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1infinitewp · infinitewp5 Oca 2015