nucleuscms kayıtları
nucleuscms üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-21474İstismar yok | File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsnucleuscms · nucleuscms · CWE-434 | Kritik9,8 | — | %1,2 | 20 Haz 2023 |
30İzleyin | CVE-2010-5041Kavram kanıtı | SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commandsjohn bradshaw · np gallery plugin · CWE-89 | Yüksek7,5 | — | %1,2 | 2 Kas 2011 |
28İzleyin | CVE-2010-5040Kavram kanıtı | PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers john bradshaw · np gallery plugin · CWE-94 | Orta6,8 | — | %2,0 | 2 Kas 2011 |
28İzleyin | CVE-2021-37770İstismar yok | Nucleus CMS v3.71 is affected by a file upload vulnerability.nucleuscms · nucleus cms · CWE-434 | Yüksek7,2 | — | %1,3 | 30 Haz 2022 |
26İzleyin | CVE-2018-16636İstismar yok | Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.nucleuscms · nucleus cms · CWE-79 | Orta6,5 | — | %1,0 | 10 Ara 2018 |
20İzleyin | CVE-2011-3760İstismar yok | Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation patnucleuscms · nucleus cms · CWE-200 | Orta5,0 | — | %1,4 | 23 Eyl 2011 |
17İzleyin | CVE-2015-5454İstismar yok | Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parametnucleuscms · nucleus cms · CWE-79 | Orta4,3 | — | %1,6 | 8 Tem 2015 |
- CVE-2020-2147439İzleyin
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rs
KritikCVSS 9,8İstismar yokEPSS %1nucleuscms · nucleuscms20 Haz 2023
- CVE-2010-504130İzleyin
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1john bradshaw · np gallery plugin2 Kas 2011
- CVE-2010-504028İzleyin
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers
OrtaCVSS 6,8Kavram kanıtıEPSS %2john bradshaw · np gallery plugin2 Kas 2011
- CVE-2021-3777028İzleyin
Nucleus CMS v3.71 is affected by a file upload vulnerability.
YüksekCVSS 7,2İstismar yokEPSS %1nucleuscms · nucleus cms30 Haz 2022
- CVE-2018-1663626İzleyin
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
OrtaCVSS 6,5İstismar yokEPSS %1nucleuscms · nucleus cms10 Ara 2018
- CVE-2011-376020İzleyin
Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat
OrtaCVSS 5,0İstismar yokEPSS %1nucleuscms · nucleus cms23 Eyl 2011
- CVE-2015-545417İzleyin
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title paramet
OrtaCVSS 4,3İstismar yokEPSS %2nucleuscms · nucleus cms8 Tem 2015