jnoj kayıtları
jnoj üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2019-17490İstismar yok | app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated byjnoj · jiangnan online judge · CWE-434 | Yüksek8,8 | — | %1,5 | 10 Eki 2019 |
33İzleyin | CVE-2019-17538Kavram kanıtı | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substringjnoj · jiangnan online judge · CWE-22 | Yüksek7,5 | — | %11,3 | 13 Eki 2019 |
30İzleyin | CVE-2019-17537İstismar yok | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substrjnoj · jiangnan online judge · CWE-22 | Yüksek7,5 | — | %1,6 | 13 Eki 2019 |
24İzleyin | CVE-2019-17493İstismar yok | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/upjnoj · jiangnan online judge · CWE-79 | Orta6,1 | — | %1,1 | 10 Eki 2019 |
24İzleyin | CVE-2019-17489İstismar yok | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update jnoj · jiangnan online judge · CWE-79 | Orta6,1 | — | %1,1 | 10 Eki 2019 |
24İzleyin | CVE-2019-17491İstismar yok | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/updjnoj · jiangnan online judge · CWE-79 | Orta6,1 | — | %1,1 | 10 Eki 2019 |
- CVE-2019-1749035İzleyin
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by
YüksekCVSS 8,8İstismar yokEPSS %1jnoj · jiangnan online judge10 Eki 2019
- CVE-2019-1753833İzleyin
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring
YüksekCVSS 7,5Kavram kanıtıEPSS %11jnoj · jiangnan online judge13 Eki 2019
- CVE-2019-1753730İzleyin
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substr
YüksekCVSS 7,5İstismar yokEPSS %2jnoj · jiangnan online judge13 Eki 2019
- CVE-2019-1749324İzleyin
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/up
OrtaCVSS 6,1İstismar yokEPSS %1jnoj · jiangnan online judge10 Eki 2019
- CVE-2019-1748924İzleyin
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update
OrtaCVSS 6,1İstismar yokEPSS %1jnoj · jiangnan online judge10 Eki 2019
- CVE-2019-1749124İzleyin
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/upd
OrtaCVSS 6,1İstismar yokEPSS %1jnoj · jiangnan online judge10 Eki 2019