nchsoftware kayıtları
nchsoftware üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-425 Direct Request ('Forced Browsing')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-522 Insufficiently Protected Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2020-11561İstismar yok | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such asnchsoftware · express invoice · CWE-425 | Yüksek8,8 | — | %2,2 | 7 Nis 2020 |
36İzleyin | CVE-2021-37444İstismar yok | NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.nchsoftware · ivm attendant · CWE-22 | Yüksek8,8 | — | %1,9 | 25 Tem 2021 |
32İzleyin | CVE-2021-37447İstismar yok | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..nchsoftware · quorum · CWE-22 | Yüksek8,1 | — | %1,6 | 25 Tem 2021 |
32İzleyin | CVE-2021-37443İstismar yok | NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.nchsoftware · ivm attendant · CWE-22 | Yüksek8,1 | — | %1,2 | 25 Tem 2021 |
31İzleyin | CVE-2020-11560Kavram kanıtı | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.nchsoftware · express invoice · CWE-522 | Yüksek7,8 | — | %1,0 | 7 Nis 2020 |
27İzleyin | CVE-2010-5220İstismar yok | Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll filenchsoftware · meo encryption software | Orta6,9 | — | %0,4 | 6 Eyl 2012 |
26İzleyin | CVE-2021-37445İstismar yok | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..nchsoftware · quorum · CWE-22 | Orta6,5 | — | %1,4 | 25 Tem 2021 |
26İzleyin | CVE-2021-37442İstismar yok | NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..nchsoftware · ivm attendant · CWE-22 | Orta6,5 | — | %1,2 | 25 Tem 2021 |
26İzleyin | CVE-2020-13474İstismar yok | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalnchsoftware · express accounts · CWE-425 | Orta6,5 | — | %0,8 | 28 Ara 2020 |
22İzleyin | CVE-2020-13473İstismar yok | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.nchsoftware · express accounts · CWE-312 | Orta5,5 | — | %0,3 | 28 Ara 2020 |
21İzleyin | CVE-2021-37451İstismar yok | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).nchsoftware · ivm attendant · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37457İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37458İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37459İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37463İstismar yok | In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).nchsoftware · quorum · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37465İstismar yok | In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).nchsoftware · quorum · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37450İstismar yok | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).nchsoftware · ivm attendant · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37462İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37464İstismar yok | In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).nchsoftware · quorum · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37453İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37454İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37455İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37456İstismar yok | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).nchsoftware · axon pbx · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37466İstismar yok | In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).nchsoftware · quorum · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
21İzleyin | CVE-2021-37467İstismar yok | In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).nchsoftware · quorum · CWE-79 | Orta5,4 | — | %0,6 | 25 Tem 2021 |
- CVE-2020-1156136İzleyin
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as
YüksekCVSS 8,8İstismar yokEPSS %2nchsoftware · express invoice7 Nis 2020
- CVE-2021-3744436İzleyin
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.
YüksekCVSS 8,8İstismar yokEPSS %2nchsoftware · ivm attendant25 Tem 2021
- CVE-2021-3744732İzleyin
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..
YüksekCVSS 8,1İstismar yokEPSS %2nchsoftware · quorum25 Tem 2021
- CVE-2021-3744332İzleyin
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
YüksekCVSS 8,1İstismar yokEPSS %1nchsoftware · ivm attendant25 Tem 2021
- CVE-2020-1156031İzleyin
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
YüksekCVSS 7,8Kavram kanıtıEPSS %1nchsoftware · express invoice7 Nis 2020
- CVE-2010-522027İzleyin
Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file
OrtaCVSS 6,9İstismar yokEPSS %0nchsoftware · meo encryption software6 Eyl 2012
- CVE-2021-3744526İzleyin
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..
OrtaCVSS 6,5İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021
- CVE-2021-3744226İzleyin
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..
OrtaCVSS 6,5İstismar yokEPSS %1nchsoftware · ivm attendant25 Tem 2021
- CVE-2020-1347426İzleyin
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functional
OrtaCVSS 6,5İstismar yokEPSS %1nchsoftware · express accounts28 Ara 2020
- CVE-2020-1347322İzleyin
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
OrtaCVSS 5,5İstismar yokEPSS %0nchsoftware · express accounts28 Ara 2020
- CVE-2021-3745121İzleyin
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · ivm attendant25 Tem 2021
- CVE-2021-3745721İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3745821İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3745921İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3746321İzleyin
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021
- CVE-2021-3746521İzleyin
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021
- CVE-2021-3745021İzleyin
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · ivm attendant25 Tem 2021
- CVE-2021-3746221İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3746421İzleyin
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021
- CVE-2021-3745321İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3745421İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3745521İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3745621İzleyin
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · axon pbx25 Tem 2021
- CVE-2021-3746621İzleyin
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021
- CVE-2021-3746721İzleyin
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
OrtaCVSS 5,4İstismar yokEPSS %1nchsoftware · quorum25 Tem 2021