open-audit kayıtları
open-audit üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2018-8979Kavram kanıtı | Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.open-audit · open-audit · CWE-79 | Yüksek8,8 | — | %1,2 | 25 Mar 2018 |
28İzleyin | CVE-2018-9137Kavram kanıtı | Open-AudIT before 2.2 has CSV Injection.open-audit · open-audit · CWE-1236 | Orta6,8 | — | %2,7 | 19 Nis 2018 |
24İzleyin | CVE-2018-8937İstismar yok | An issue was discovered in Open-AudIT Professional 2.1.open-audit · open-audit · CWE-601 | Orta6,1 | — | %0,7 | 26 Mar 2018 |
21İzleyin | CVE-2018-8903Kavram kanıtı | Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.open-audit · open-audit · CWE-79 | Orta5,4 | — | %1,6 | 22 Mar 2018 |
21İzleyin | CVE-2018-9155Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML viaopen-audit · open-audit · CWE-79 | Orta5,4 | — | %1,1 | 12 Nis 2018 |
21İzleyin | CVE-2018-8978İstismar yok | Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.open-audit · open-audit · CWE-79 | Orta5,4 | — | %0,5 | 25 Mar 2018 |
- CVE-2018-897935İzleyin
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
YüksekCVSS 8,8Kavram kanıtıEPSS %1open-audit · open-audit25 Mar 2018
- CVE-2018-913728İzleyin
Open-AudIT before 2.2 has CSV Injection.
OrtaCVSS 6,8Kavram kanıtıEPSS %3open-audit · open-audit19 Nis 2018
- CVE-2018-893724İzleyin
An issue was discovered in Open-AudIT Professional 2.1.
OrtaCVSS 6,1İstismar yokEPSS %1open-audit · open-audit26 Mar 2018
- CVE-2018-890321İzleyin
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
OrtaCVSS 5,4Kavram kanıtıEPSS %2open-audit · open-audit22 Mar 2018
- CVE-2018-915521İzleyin
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 5,4Kavram kanıtıEPSS %1open-audit · open-audit12 Nis 2018
- CVE-2018-897821İzleyin
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
OrtaCVSS 5,4İstismar yokEPSS %1open-audit · open-audit25 Mar 2018