machform kayıtları
machform üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2018-6411Kavram kanıtı | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-434 | Kritik9,8 | — | %5,8 | 26 May 2018 |
40Planlayın | CVE-2018-6410Kavram kanıtı | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-89 | Kritik9,8 | — | %4,9 | 26 May 2018 |
39İzleyin | CVE-2024-37762Kavram kanıtı | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.machform · machform · CWE-434 | Kritik9,9 | — | %1,5 | 1 Tem 2024 |
35İzleyin | CVE-2024-37765Kavram kanıtı | Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.machform · machform · CWE-89 | Yüksek8,8 | — | %0,8 | 1 Tem 2024 |
35İzleyin | CVE-2021-20102İstismar yok | Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.machform · machform · CWE-352 | Yüksek8,8 | — | %0,5 | 29 Haz 2021 |
33İzleyin | CVE-2021-20104İstismar yok | Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uplmachform · machform · CWE-434 | Yüksek8,1 | — | %2,2 | 29 Haz 2021 |
31İzleyin | CVE-2013-4948Kavram kanıtı | SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.machform · machform · CWE-89 | Yüksek7,5 | — | %3,5 | 29 Tem 2013 |
29İzleyin | CVE-2013-4949Kavram kanıtı | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fimachform · machform | Orta6,8 | — | %5,5 | 29 Tem 2013 |
25İzleyin | CVE-2018-6409Kavram kanıtı | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-22 | Orta5,3 | — | %14,6 | 26 May 2018 |
24İzleyin | CVE-2021-20105İstismar yok | Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.machform · machform · CWE-601 | Orta6,1 | — | %0,7 | 29 Haz 2021 |
24İzleyin | CVE-2021-20101İstismar yok | Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.machform · machform · CWE-74 | Orta6,1 | — | %0,7 | 29 Haz 2021 |
24İzleyin | CVE-2021-20103İstismar yok | Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded withmachform · machform · CWE-79 | Orta6,1 | — | %0,7 | 29 Haz 2021 |
21İzleyin | CVE-2024-37763Kavram kanıtı | MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can viemachform · machform · CWE-79 | Orta5,4 | — | %0,7 | 1 Tem 2024 |
21İzleyin | CVE-2024-37764Kavram kanıtı | MachForm up to version 19 is affected by an authenticated stored cross-site scripting.machform · machform · CWE-79 | Orta5,4 | — | %0,6 | 1 Tem 2024 |
18İzleyin | CVE-2013-4950Kavram kanıtı | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the elmachform · machform · CWE-79 | Orta4,3 | — | %3,9 | 29 Tem 2013 |
- CVE-2018-641141Planlayın
An issue was discovered in Appnitro MachForm before 4.2.3.
KritikCVSS 9,8Kavram kanıtıEPSS %6machform · machform26 May 2018
- CVE-2018-641040Planlayın
An issue was discovered in Appnitro MachForm before 4.2.3.
KritikCVSS 9,8Kavram kanıtıEPSS %5machform · machform26 May 2018
- CVE-2024-3776239İzleyin
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
KritikCVSS 9,9Kavram kanıtıEPSS %1machform · machform1 Tem 2024
- CVE-2024-3776535İzleyin
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
YüksekCVSS 8,8Kavram kanıtıEPSS %1machform · machform1 Tem 2024
- CVE-2021-2010235İzleyin
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
YüksekCVSS 8,8İstismar yokEPSS %1machform · machform29 Haz 2021
- CVE-2021-2010433İzleyin
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments upl
YüksekCVSS 8,1İstismar yokEPSS %2machform · machform29 Haz 2021
- CVE-2013-494831İzleyin
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %3machform · machform29 Tem 2013
- CVE-2013-494929İzleyin
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fi
OrtaCVSS 6,8Kavram kanıtıEPSS %5machform · machform29 Tem 2013
- CVE-2018-640925İzleyin
An issue was discovered in Appnitro MachForm before 4.2.3.
OrtaCVSS 5,3Kavram kanıtıEPSS %15machform · machform26 May 2018
- CVE-2021-2010524İzleyin
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
OrtaCVSS 6,1İstismar yokEPSS %1machform · machform29 Haz 2021
- CVE-2021-2010124İzleyin
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.
OrtaCVSS 6,1İstismar yokEPSS %1machform · machform29 Haz 2021
- CVE-2021-2010324İzleyin
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with
OrtaCVSS 6,1İstismar yokEPSS %1machform · machform29 Haz 2021
- CVE-2024-3776321İzleyin
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can vie
OrtaCVSS 5,4Kavram kanıtıEPSS %1machform · machform1 Tem 2024
- CVE-2024-3776421İzleyin
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
OrtaCVSS 5,4Kavram kanıtıEPSS %1machform · machform1 Tem 2024
- CVE-2013-495018İzleyin
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the el
OrtaCVSS 4,3Kavram kanıtıEPSS %4machform · machform29 Tem 2013