opensymphony kayıtları
opensymphony üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2007-4556Kavram kanıtı | Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all inpopensymphony · xwork | Orta6,8 | — | %25,7 | 27 Ağu 2007 |
31İzleyin | CVE-2008-6504Kavram kanıtı | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does notopensymphony · xwork · CWE-20 | Orta5,0 | — | %36,6 | 23 Mar 2009 |
22İzleyin | CVE-2011-2088İstismar yok | XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive apache · struts · CWE-200 | Orta5,0 | — | %6,1 | 13 May 2011 |
20İzleyin | CVE-2011-1772Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWoapache · struts · CWE-79 | Düşük2,6 | — | %33,3 | 13 May 2011 |
- CVE-2007-455635İzleyin
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all inp
OrtaCVSS 6,8Kavram kanıtıEPSS %26opensymphony · xwork27 Ağu 2007
- CVE-2008-650431İzleyin
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not
OrtaCVSS 5,0Kavram kanıtıEPSS %37opensymphony · xwork23 Mar 2009
- CVE-2011-208822İzleyin
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive
OrtaCVSS 5,0İstismar yokEPSS %6apache · struts13 May 2011
- CVE-2011-177220İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWo
DüşükCVSS 2,6Kavram kanıtıEPSS %33apache · struts13 May 2011