packetfence kayıtları
packetfence üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2011-4069İstismar yok | html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authenticpacketfence · packetfence · CWE-90 | Kritik9,8 | — | %1,6 | 1 Şub 2018 |
39İzleyin | CVE-2011-4068İstismar yok | The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an emptpacketfence · packetfence · CWE-287 | Kritik9,8 | — | %1,5 | 1 Şub 2018 |
31İzleyin | CVE-2012-4742İstismar yok | The web_node_register function in web.pm in PacketFence before 3.0.2 might allow remote attackers to execute arbitrary code via unspecified packetfence · packetfence | Yüksek7,5 | — | %2,7 | 31 Ağu 2012 |
20İzleyin | CVE-2012-4741İstismar yok | The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assigpacketfence · packetfence · CWE-287 | Orta5,0 | — | %1,4 | 31 Ağu 2012 |
17İzleyin | CVE-2012-4740İstismar yok | Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to inject arbitrary web spacketfence · packetfence · CWE-79 | Orta4,3 | — | %1,2 | 31 Ağu 2012 |
- CVE-2011-406939İzleyin
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic
KritikCVSS 9,8İstismar yokEPSS %2packetfence · packetfence1 Şub 2018
- CVE-2011-406839İzleyin
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empt
KritikCVSS 9,8İstismar yokEPSS %2packetfence · packetfence1 Şub 2018
- CVE-2012-474231İzleyin
The web_node_register function in web.pm in PacketFence before 3.0.2 might allow remote attackers to execute arbitrary code via unspecified
YüksekCVSS 7,5İstismar yokEPSS %3packetfence · packetfence31 Ağu 2012
- CVE-2012-474120İzleyin
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assig
OrtaCVSS 5,0İstismar yokEPSS %1packetfence · packetfence31 Ağu 2012
- CVE-2012-474017İzleyin
Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to inject arbitrary web s
OrtaCVSS 4,3İstismar yokEPSS %1packetfence · packetfence31 Ağu 2012