mkcms project kayıtları
mkcms project üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-10707İstismar yok | MKCMS V5.0 has SQL injection via the bplay.php play parameter.mkcms project · mkcms · CWE-89 | Kritik9,8 | — | %1,5 | 2 Nis 2019 |
39İzleyin | CVE-2020-22818İstismar yok | MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.mkcms project · mkcms · CWE-89 | Kritik9,8 | — | %0,9 | 3 Kas 2022 |
39İzleyin | CVE-2020-22819İstismar yok | MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.mkcms project · mkcms · CWE-89 | Kritik9,8 | — | %0,9 | 3 Kas 2022 |
39İzleyin | CVE-2020-22820İstismar yok | MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.mkcms project · mkcms · CWE-89 | Kritik9,8 | — | %0,9 | 3 Kas 2022 |
36İzleyin | CVE-2019-11332İstismar yok | MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, whichmkcms project · mkcms | Yüksek8,8 | — | %1,8 | 18 Nis 2019 |
35İzleyin | CVE-2019-11078İstismar yok | MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.mkcms project · mkcms · CWE-352 | Yüksek8,8 | — | %0,6 | 10 Nis 2019 |
- CVE-2019-1070739İzleyin
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
KritikCVSS 9,8İstismar yokEPSS %1mkcms project · mkcms2 Nis 2019
- CVE-2020-2281839İzleyin
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
KritikCVSS 9,8İstismar yokEPSS %1mkcms project · mkcms3 Kas 2022
- CVE-2020-2281939İzleyin
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
KritikCVSS 9,8İstismar yokEPSS %1mkcms project · mkcms3 Kas 2022
- CVE-2020-2282039İzleyin
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
KritikCVSS 9,8İstismar yokEPSS %1mkcms project · mkcms3 Kas 2022
- CVE-2019-1133236İzleyin
MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which
YüksekCVSS 8,8İstismar yokEPSS %2mkcms project · mkcms18 Nis 2019
- CVE-2019-1107835İzleyin
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
YüksekCVSS 8,8İstismar yokEPSS %1mkcms project · mkcms10 Nis 2019