mozilo kayıtları
mozilo üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %5,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2022-23357İstismar yok | mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.mozilo · mozilocms · CWE-22 | Kritik9,1 | — | %19,9 | 2 Şub 2022 |
33İzleyin | CVE-2024-44871Kavram kanıtı | An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via upmozilo · mozilocms · CWE-434 | Yüksek7,2 | — | %16,2 | 10 Eyl 2024 |
32İzleyin | CVE-2009-1368Kavram kanıtı | Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a ..mozilo · mozilocms · CWE-22 | Yüksek7,5 | — | %6,2 | 22 Nis 2009 |
27İzleyin | CVE-2008-6128İstismar yok | Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parammozilo · mozilocms · CWE-287 | Orta6,8 | — | %1,3 | 13 Şub 2009 |
26İzleyin | CVE-2024-29368İstismar yok | An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via fmozilo · mozilocms · CWE-434 | Orta6,5 | — | %0,8 | 22 Nis 2024 |
24İzleyin | CVE-2008-6131İstismar yok | Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parammozilo · mozilowiki · CWE-287 | Orta6,0 | — | %1,2 | 13 Şub 2009 |
24İzleyin | CVE-2024-44872İstismar yok | A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user'smozilo · mozilocms · CWE-79 | Orta6,1 | — | %0,5 | 10 Eyl 2024 |
24İzleyin | CVE-2024-2245İstismar yok | Cross-Site Scripting vulnerability in moziloCMSmozilo · mozilocms · CWE-79 | Orta6,1 | — | %0,3 | 7 Mar 2024 |
21İzleyin | CVE-2008-6126Kavram kanıtı | Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a ..mozilo · mozilocms · CWE-22 | Orta5,0 | — | %2,9 | 13 Şub 2009 |
21İzleyin | CVE-2009-1369Kavram kanıtı | moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] mozilo · mozilocms · CWE-20 | Orta5,0 | — | %2,4 | 22 Nis 2009 |
21İzleyin | CVE-2020-25394İstismar yok | A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML vmozilo · mozilocms · CWE-79 | Orta5,4 | — | %0,4 | 9 Tem 2021 |
18İzleyin | CVE-2008-3589Kavram kanıtı | Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read armozilo · mozilocms · CWE-22 | Orta4,3 | — | %2,4 | 11 Ağu 2008 |
17İzleyin | CVE-2008-6129İstismar yok | Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a ..mozilo · mozilowiki · CWE-22 | Orta4,3 | — | %1,6 | 13 Şub 2009 |
17İzleyin | CVE-2009-1367Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via tmozilo · mozilocms · CWE-79 | Orta4,3 | — | %1,5 | 22 Nis 2009 |
17İzleyin | CVE-2008-6130İstismar yok | Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web scriptmozilo · mozilowiki · CWE-79 | Orta4,3 | — | %1,2 | 13 Şub 2009 |
17İzleyin | CVE-2009-4209Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web scmozilo · mozilocms · CWE-79 | Orta4,3 | — | %1,2 | 4 Ara 2009 |
17İzleyin | CVE-2008-6127İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script ormozilo · mozilocms · CWE-79 | Orta4,3 | — | %1,1 | 13 Şub 2009 |
- CVE-2022-2335742Planlayın
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
KritikCVSS 9,1İstismar yokEPSS %20mozilo · mozilocms2 Şub 2022
- CVE-2024-4487133İzleyin
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via up
YüksekCVSS 7,2Kavram kanıtıEPSS %16mozilo · mozilocms10 Eyl 2024
- CVE-2009-136832İzleyin
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a ..
YüksekCVSS 7,5Kavram kanıtıEPSS %6mozilo · mozilocms22 Nis 2009
- CVE-2008-612827İzleyin
Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID param
OrtaCVSS 6,8İstismar yokEPSS %1mozilo · mozilocms13 Şub 2009
- CVE-2024-2936826İzleyin
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via f
OrtaCVSS 6,5İstismar yokEPSS %1mozilo · mozilocms22 Nis 2024
- CVE-2008-613124İzleyin
Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID param
OrtaCVSS 6,0İstismar yokEPSS %1mozilo · mozilowiki13 Şub 2009
- CVE-2024-4487224İzleyin
A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's
OrtaCVSS 6,1İstismar yokEPSS %0mozilo · mozilocms10 Eyl 2024
- CVE-2024-224524İzleyin
Cross-Site Scripting vulnerability in moziloCMS
OrtaCVSS 6,1İstismar yokEPSS %0mozilo · mozilocms7 Mar 2024
- CVE-2008-612621İzleyin
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %3mozilo · mozilocms13 Şub 2009
- CVE-2009-136921İzleyin
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[]
OrtaCVSS 5,0Kavram kanıtıEPSS %2mozilo · mozilocms22 Nis 2009
- CVE-2020-2539421İzleyin
A stored cross site scripting (XSS) vulnerability in moziloCMS 2.0 allows authenticated attackers to execute arbitrary web scripts or HTML v
OrtaCVSS 5,4İstismar yokEPSS %0mozilo · mozilocms9 Tem 2021
- CVE-2008-358918İzleyin
Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read ar
OrtaCVSS 4,3Kavram kanıtıEPSS %2mozilo · mozilocms11 Ağu 2008
- CVE-2008-612917İzleyin
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a ..
OrtaCVSS 4,3İstismar yokEPSS %2mozilo · mozilowiki13 Şub 2009
- CVE-2009-136717İzleyin
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 4,3Kavram kanıtıEPSS %1mozilo · mozilocms22 Nis 2009
- CVE-2008-613017İzleyin
Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1mozilo · mozilowiki13 Şub 2009
- CVE-2009-420917İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web sc
OrtaCVSS 4,3Kavram kanıtıEPSS %1mozilo · mozilocms4 Ara 2009
- CVE-2008-612717İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %1mozilo · mozilocms13 Şub 2009