oneclickorgs kayıtları
oneclickorgs üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-20 Improper Input Validation2
- CWE-255 Credentials Management Errors2
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2011-4677İstismar yok | One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackeroneclickorgs · one click orgs · CWE-287 | Yüksek7,5 | — | %1,3 | 6 Ara 2011 |
23İzleyin | CVE-2011-4553İstismar yok | Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites anoneclickorgs · one click orgs · CWE-20 | Orta5,8 | — | %0,9 | 6 Ara 2011 |
22İzleyin | CVE-2011-4554İstismar yok | One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characteroneclickorgs · one click orgs · CWE-20 | Orta5,5 | — | %0,9 | 6 Ara 2011 |
20İzleyin | CVE-2011-4678İstismar yok | The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether oneclickorgs · one click orgs · CWE-255 | Orta5,0 | — | %1,1 | 6 Ara 2011 |
17İzleyin | CVE-2011-4552İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbitrary web script or oneclickorgs · one click orgs · CWE-79 | Orta4,3 | — | %0,8 | 6 Ara 2011 |
16İzleyin | CVE-2011-4555İstismar yok | One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a doneclickorgs · one click orgs · CWE-255 | Orta4,0 | — | %0,9 | 6 Ara 2011 |
- CVE-2011-467730İzleyin
One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attacker
YüksekCVSS 7,5İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011
- CVE-2011-455323İzleyin
Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites an
OrtaCVSS 5,8İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011
- CVE-2011-455422İzleyin
One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline character
OrtaCVSS 5,5İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011
- CVE-2011-467820İzleyin
The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether
OrtaCVSS 5,0İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011
- CVE-2011-455217İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011
- CVE-2011-455516İzleyin
One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a d
OrtaCVSS 4,0İstismar yokEPSS %1oneclickorgs · one click orgs6 Ara 2011