inxedu kayıtları
inxedu üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2020-35326İstismar yok | SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0inxedu · inxedu · CWE-89 | Kritik9,8 | — | %13,6 | 18 Oca 2023 |
40Planlayın | CVE-2019-7684İstismar yok | inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.inxedu · inxedu · CWE-434 | Kritik9,8 | — | %2,1 | 9 Şub 2019 |
39İzleyin | CVE-2020-35430İstismar yok | SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystinxedu · inxedu · CWE-89 | Kritik9,8 | — | %1,1 | 29 Nis 2021 |
39İzleyin | CVE-2024-35570İstismar yok | An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to executeinxedu · inxedu · CWE-434 | Kritik9,8 | — | %0,9 | 23 May 2024 |
39İzleyin | CVE-2020-21152İstismar yok | SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctioinxedu · inxedu · CWE-89 | Kritik9,8 | — | %0,8 | 20 Oca 2023 |
39İzleyin | CVE-2024-35079İstismar yok | An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading inxedu · inxedu · CWE-434 | Kritik9,8 | — | %0,6 | 23 May 2024 |
39İzleyin | CVE-2024-35080İstismar yok | An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craftinxedu · inxedu · CWE-434 | Kritik9,8 | — | %0,6 | 23 May 2024 |
- CVE-2020-3532643Planlayın
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0
KritikCVSS 9,8İstismar yokEPSS %14inxedu · inxedu18 Oca 2023
- CVE-2019-768440Planlayın
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.
KritikCVSS 9,8İstismar yokEPSS %2inxedu · inxedu9 Şub 2019
- CVE-2020-3543039İzleyin
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsyst
KritikCVSS 9,8İstismar yokEPSS %1inxedu · inxedu29 Nis 2021
- CVE-2024-3557039İzleyin
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute
KritikCVSS 9,8İstismar yokEPSS %1inxedu · inxedu23 May 2024
- CVE-2020-2115239İzleyin
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctio
KritikCVSS 9,8İstismar yokEPSS %1inxedu · inxedu20 Oca 2023
- CVE-2024-3507939İzleyin
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading
KritikCVSS 9,8İstismar yokEPSS %1inxedu · inxedu23 May 2024
- CVE-2024-3508039İzleyin
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craft
KritikCVSS 9,8İstismar yokEPSS %1inxedu · inxedu23 May 2024