joyplus-cms project kayıtları
joyplus-cms project üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-12039İstismar yok | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "joyplus-cms project · joyplus-cms · CWE-89 | Kritik9,8 | — | %4,7 | 7 Haz 2018 |
40Planlayın | CVE-2018-8766İstismar yok | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/adjoyplus-cms project · joyplus-cms · CWE-434 | Kritik9,8 | — | %3,3 | 18 Mar 2018 |
39İzleyin | CVE-2018-14334İstismar yok | manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets thejoyplus-cms project · joyplus-cms · CWE-434 | Kritik9,8 | — | %1,7 | 16 Tem 2018 |
39İzleyin | CVE-2018-14389İstismar yok | joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.joyplus-cms project · joyplus-cms · CWE-89 | Kritik9,8 | — | %1,5 | 18 Tem 2018 |
37İzleyin | CVE-2018-12905İstismar yok | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.joyplus-cms project · joyplus-cms · CWE-79 | Orta6,1 | — | %42,2 | 27 Haz 2018 |
35İzleyin | CVE-2018-8717İstismar yok | joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager reqjoyplus-cms project · joyplus-cms · CWE-352 | Yüksek8,8 | — | %0,6 | 14 Mar 2018 |
31İzleyin | CVE-2019-17175İstismar yok | joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.joyplus-cms project · joyplus-cms · CWE-22 | Yüksek7,5 | — | %1,7 | 4 Eki 2019 |
30İzleyin | CVE-2020-22124İstismar yok | A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.joyplus-cms project · joyplus-cms · CWE-552 | Yüksek7,5 | — | %1,0 | 18 Ağu 2021 |
30İzleyin | CVE-2020-20636İstismar yok | SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of thjoyplus-cms project · joyplus-cms · CWE-89 | Yüksek7,5 | — | %0,7 | 20 Haz 2023 |
24İzleyin | CVE-2018-14500İstismar yok | joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.joyplus-cms project · joyplus-cms · CWE-79 | Orta6,1 | — | %0,8 | 22 Tem 2018 |
21İzleyin | CVE-2018-10028İstismar yok | joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.joyplus-cms project · joyplus-cms · CWE-200 | Orta5,3 | — | %1,5 | 11 Nis 2018 |
21İzleyin | CVE-2018-14388İstismar yok | joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.joyplus-cms project · joyplus-cms · CWE-79 | Orta5,4 | — | %0,8 | 18 Tem 2018 |
19İzleyin | CVE-2018-8767İstismar yok | joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter.joyplus-cms project · joyplus-cms · CWE-79 | Orta4,8 | — | %0,6 | 18 Mar 2018 |
19İzleyin | CVE-2018-10096İstismar yok | joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.joyplus-cms project · joyplus-cms · CWE-79 | Orta4,8 | — | %0,6 | 13 Nis 2018 |
19İzleyin | CVE-2018-10073İstismar yok | joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.joyplus-cms project · joyplus-cms · CWE-79 | Orta4,8 | — | %0,6 | 12 Nis 2018 |
- CVE-2018-1203940Planlayın
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "
KritikCVSS 9,8İstismar yokEPSS %5joyplus-cms project · joyplus-cms7 Haz 2018
- CVE-2018-876640Planlayın
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/ad
KritikCVSS 9,8İstismar yokEPSS %3joyplus-cms project · joyplus-cms18 Mar 2018
- CVE-2018-1433439İzleyin
manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the
KritikCVSS 9,8İstismar yokEPSS %2joyplus-cms project · joyplus-cms16 Tem 2018
- CVE-2018-1438939İzleyin
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
KritikCVSS 9,8İstismar yokEPSS %1joyplus-cms project · joyplus-cms18 Tem 2018
- CVE-2018-1290537İzleyin
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
OrtaCVSS 6,1İstismar yokEPSS %42joyplus-cms project · joyplus-cms27 Haz 2018
- CVE-2018-871735İzleyin
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager req
YüksekCVSS 8,8İstismar yokEPSS %1joyplus-cms project · joyplus-cms14 Mar 2018
- CVE-2019-1717531İzleyin
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
YüksekCVSS 7,5İstismar yokEPSS %2joyplus-cms project · joyplus-cms4 Eki 2019
- CVE-2020-2212430İzleyin
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
YüksekCVSS 7,5İstismar yokEPSS %1joyplus-cms project · joyplus-cms18 Ağu 2021
- CVE-2020-2063630İzleyin
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of th
YüksekCVSS 7,5İstismar yokEPSS %1joyplus-cms project · joyplus-cms20 Haz 2023
- CVE-2018-1450024İzleyin
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
OrtaCVSS 6,1İstismar yokEPSS %1joyplus-cms project · joyplus-cms22 Tem 2018
- CVE-2018-1002821İzleyin
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
OrtaCVSS 5,3İstismar yokEPSS %1joyplus-cms project · joyplus-cms11 Nis 2018
- CVE-2018-1438821İzleyin
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
OrtaCVSS 5,4İstismar yokEPSS %1joyplus-cms project · joyplus-cms18 Tem 2018
- CVE-2018-876719İzleyin
joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter.
OrtaCVSS 4,8İstismar yokEPSS %1joyplus-cms project · joyplus-cms18 Mar 2018
- CVE-2018-1009619İzleyin
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.
OrtaCVSS 4,8İstismar yokEPSS %1joyplus-cms project · joyplus-cms13 Nis 2018
- CVE-2018-1007319İzleyin
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
OrtaCVSS 4,8İstismar yokEPSS %1joyplus-cms project · joyplus-cms12 Nis 2018