pearson kayıtları
pearson üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-255 Credentials Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2020-36154İstismar yok | The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" dpearson · vue testing system · CWE-732 | Yüksek7,8 | — | %0,4 | 4 Oca 2021 |
30İzleyin | CVE-2014-1455İstismar yok | SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 andpearson · esis enterprise student information system · CWE-89 | Yüksek7,5 | — | %1,3 | 10 Nis 2014 |
20İzleyin | CVE-2015-0972İstismar yok | Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackpearson · proctorcache · CWE-255 | Orta5,0 | — | %1,4 | 23 Haz 2015 |
19İzleyin | CVE-2014-1454İstismar yok | Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user inputpearson · esis enterprise student information system · CWE-79 | Orta4,8 | — | %0,6 | 8 Oca 2020 |
17İzleyin | CVE-2014-1942İstismar yok | Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote apearson · esis enterprise student information system · CWE-79 | Orta4,3 | — | %1,0 | 1 Nis 2014 |
- CVE-2020-3615431İzleyin
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" d
YüksekCVSS 7,8İstismar yokEPSS %0pearson · vue testing system4 Oca 2021
- CVE-2014-145530İzleyin
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and
YüksekCVSS 7,5İstismar yokEPSS %1pearson · esis enterprise student information system10 Nis 2014
- CVE-2015-097220İzleyin
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attack
OrtaCVSS 5,0İstismar yokEPSS %1pearson · proctorcache23 Haz 2015
- CVE-2014-145419İzleyin
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
OrtaCVSS 4,8İstismar yokEPSS %1pearson · esis enterprise student information system8 Oca 2020
- CVE-2014-194217İzleyin
Cross-site scripting (XSS) vulnerability in aal/loginverification.aspx in Pearson eSIS Enterprise Student Information System allows remote a
OrtaCVSS 4,3İstismar yokEPSS %1pearson · esis enterprise student information system1 Nis 2014