İçeriğe atla
Noroxi

playsms kayıtları

playsms üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %7,1
Silahlaştırılmış
3 · %21,4
Pre-auth RCE
6
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
637 gün

Tüm kayıtlar

14 kayıt
  • PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87

    playsms · playsms5 Şub 2020

  • CVE-2017-9101
    62Bu hafta

    import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a

    KritikCVSS 9,8SilahlaştırılmışEPSS %77

    playsms · playsms21 May 2017

  • CVE-2017-9080
    54Planlayın

    PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %62

    playsms · playsms19 May 2017

  • CVE-2021-40373
    40Planlayın

    playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    playsms · playsms10 Eyl 2021

  • CVE-2022-47034
    39İzleyin

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

    KritikCVSS 9,8İstismar yokEPSS %1

    playsms · playsms13 Şub 2023

  • CVE-2009-0103
    33İzleyin

    Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    playsms · playsms9 Oca 2009

  • CVE-2008-5881
    32İzleyin

    Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    playsms · playsms9 Oca 2009

  • CVE-2004-2263
    30İzleyin

    SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    playsms · playsms31 Ara 2004

  • CVE-2020-15018
    26İzleyin

    playSMS through 1.4.3 is vulnerable to session fixation.

    OrtaCVSS 6,5İstismar yokEPSS %1

    playsms · playsms24 Haz 2020

  • CVE-2024-8880
    25İzleyin

    playSMS Template index.php code injection

    OrtaCVSS 6,3İstismar yokEPSS %1

    playsms · playsms15 Eyl 2024

  • CVE-2024-6469
    20İzleyin

    playSMS Template injection

    OrtaCVSS 5,1İstismar yokEPSS %1

    playsms · playsms3 Tem 2024

  • CVE-2024-6470
    20İzleyin

    playSMS Template injection

    OrtaCVSS 5,1İstismar yokEPSS %0

    playsms · playsms3 Tem 2024

  • CVE-2024-6251
    20İzleyin

    playSMS New Phonebook cross site scripting

    OrtaCVSS 5,1İstismar yokEPSS %0

    playsms · playsms22 Haz 2024

  • CVE-2005-4432
    18İzleyin

    Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    playsms · playsms20 Ara 2005