onefilecms kayıtları
onefilecms üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2018-13123İstismar yok | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated byonefilecms · onefilecms · CWE-200 | Kritik9,8 | — | %1,4 | 3 Tem 2018 |
39İzleyin | CVE-2018-12993İstismar yok | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefileonefilecms · onefilecms · CWE-307 | Kritik9,8 | — | %1,2 | 29 Haz 2018 |
35İzleyin | CVE-2018-12994İstismar yok | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screonefilecms · onefilecms · CWE-94 | Yüksek8,8 | — | %1,2 | 29 Haz 2018 |
35İzleyin | CVE-2018-12995İstismar yok | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screenonefilecms · onefilecms · CWE-94 | Yüksek8,8 | — | %1,2 | 29 Haz 2018 |
26İzleyin | CVE-2018-13122İstismar yok | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstratonefilecms · onefilecms · CWE-732 | Orta6,5 | — | %0,8 | 3 Tem 2018 |
19İzleyin | CVE-2019-8408İstismar yok | OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.onefilecms · onefilecms | Orta4,9 | — | %1,2 | 17 Şub 2019 |
- CVE-2018-1312339İzleyin
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by
KritikCVSS 9,8İstismar yokEPSS %1onefilecms · onefilecms3 Tem 2018
- CVE-2018-1299339İzleyin
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefile
KritikCVSS 9,8İstismar yokEPSS %1onefilecms · onefilecms29 Haz 2018
- CVE-2018-1299435İzleyin
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File scre
YüksekCVSS 8,8İstismar yokEPSS %1onefilecms · onefilecms29 Haz 2018
- CVE-2018-1299535İzleyin
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen
YüksekCVSS 8,8İstismar yokEPSS %1onefilecms · onefilecms29 Haz 2018
- CVE-2018-1312226İzleyin
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrat
OrtaCVSS 6,5İstismar yokEPSS %1onefilecms · onefilecms3 Tem 2018
- CVE-2019-840819İzleyin
OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.
OrtaCVSS 4,9İstismar yokEPSS %1onefilecms · onefilecms17 Şub 2019