nch kayıtları
nch üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-426 Untrusted Search Path1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2021-37441İstismar yok | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..nch · axon pbx · CWE-22 | Yüksek8,8 | — | %1,5 | 25 Tem 2021 |
33İzleyin | CVE-2018-11552İstismar yok | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.nch · axon pbx · CWE-79 | Orta6,1 | — | %28,6 | 1 Haz 2018 |
32İzleyin | CVE-2018-11551İstismar yok | AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tarnch · axon pbx · CWE-426 | Yüksek7,8 | — | %2,5 | 1 Haz 2018 |
26İzleyin | CVE-2021-37469İstismar yok | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..nch · webdictate · CWE-22 | Orta6,5 | — | %1,2 | 25 Tem 2021 |
26İzleyin | CVE-2021-37440İstismar yok | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..nch · axon pbx · CWE-22 | Orta6,5 | — | %1,2 | 25 Tem 2021 |
26İzleyin | CVE-2021-37439İstismar yok | NCH FlexiServer v6.00 suffers from a syslog?file=/..nch · flexiserver · CWE-22 | Orta6,5 | — | %1,2 | 25 Tem 2021 |
22İzleyin | CVE-2021-37452İstismar yok | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configurnch · quorum · CWE-312 | Orta5,5 | — | %0,3 | 25 Tem 2021 |
18İzleyin | CVE-2009-4038İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrarnch · axon virtual pbx · CWE-79 | Orta4,3 | — | %2,4 | 20 Kas 2009 |
13İzleyin | CVE-2021-37468İstismar yok | NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.nch · reflect customer relationship management · CWE-312 | Düşük3,3 | — | %0,2 | 25 Tem 2021 |
- CVE-2021-3744135İzleyin
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/..
YüksekCVSS 8,8İstismar yokEPSS %1nch · axon pbx25 Tem 2021
- CVE-2018-1155233İzleyin
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field.
OrtaCVSS 6,1İstismar yokEPSS %29nch · axon pbx1 Haz 2018
- CVE-2018-1155132İzleyin
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a tar
YüksekCVSS 7,8İstismar yokEPSS %2nch · axon pbx1 Haz 2018
- CVE-2021-3746926İzleyin
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/..
OrtaCVSS 6,5İstismar yokEPSS %1nch · webdictate25 Tem 2021
- CVE-2021-3744026İzleyin
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/..
OrtaCVSS 6,5İstismar yokEPSS %1nch · axon pbx25 Tem 2021
- CVE-2021-3743926İzleyin
NCH FlexiServer v6.00 suffers from a syslog?file=/..
OrtaCVSS 6,5İstismar yokEPSS %1nch · flexiserver25 Tem 2021
- CVE-2021-3745222İzleyin
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configur
OrtaCVSS 5,5İstismar yokEPSS %0nch · quorum25 Tem 2021
- CVE-2009-403818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrar
OrtaCVSS 4,3İstismar yokEPSS %2nch · axon virtual pbx20 Kas 2009
- CVE-2021-3746813İzleyin
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
DüşükCVSS 3,3İstismar yokEPSS %0nch · reflect customer relationship management25 Tem 2021