positive software kayıtları
positive software üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-2633İstismar yok | Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files positive software · sitestudio | Kritik10,0 | — | %2,4 | 13 May 2007 |
40Planlayın | CVE-2008-1049İstismar yok | Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and positive software · h-sphere | Kritik10,0 | — | %1,5 | 27 Şub 2008 |
33İzleyin | CVE-2003-1247Kavram kanıtı | Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::positive software · h-sphere | Yüksek7,5 | — | %10,0 | 31 Ara 2003 |
32İzleyin | CVE-2005-4261İstismar yok | Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectpositive software · cp\+ | Yüksek7,8 | — | %1,7 | 15 Ara 2005 |
31İzleyin | CVE-2003-1248İstismar yok | H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parametpositive software · h-sphere | Yüksek7,5 | — | %2,2 | 31 Ara 2003 |
27İzleyin | CVE-2005-1605İstismar yok | Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML positive software · sitestudio | Orta6,8 | — | %1,5 | 16 May 2005 |
27İzleyin | CVE-2008-4448İstismar yok | Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perfpositive software · h-sphere · CWE-352 | Orta6,8 | — | %0,7 | 6 Eki 2008 |
27İzleyin | CVE-2006-6382İstismar yok | The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which apositive software · h-sphere | Orta6,8 | — | %0,3 | 7 Ara 2006 |
18İzleyin | CVE-2005-1606Kavram kanıtı | H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, whipositive software · h-sphere winbox | Orta4,6 | — | %0,8 | 16 May 2005 |
17İzleyin | CVE-2008-4447Kavram kanıtı | Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbipositive software · h-sphere · CWE-79 | Orta4,3 | — | %1,4 | 6 Eki 2008 |
17İzleyin | CVE-2006-0193İstismar yok | Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earpositive software · h-sphere | Orta4,3 | — | %1,3 | 13 Oca 2006 |
10İzleyin | CVE-2006-3278İstismar yok | Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTMLpositive software · h-sphere | Düşük2,6 | — | %1,3 | 28 Haz 2006 |
- CVE-2007-263341Planlayın
Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files
KritikCVSS 10,0İstismar yokEPSS %2positive software · sitestudio13 May 2007
- CVE-2008-104940Planlayın
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and
KritikCVSS 10,0İstismar yokEPSS %2positive software · h-sphere27 Şub 2008
- CVE-2003-124733İzleyin
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::
YüksekCVSS 7,5Kavram kanıtıEPSS %10positive software · h-sphere31 Ara 2003
- CVE-2005-426132İzleyin
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vect
YüksekCVSS 7,8İstismar yokEPSS %2positive software · cp\+15 Ara 2005
- CVE-2003-124831İzleyin
H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile paramet
YüksekCVSS 7,5İstismar yokEPSS %2positive software · h-sphere31 Ara 2003
- CVE-2005-160527İzleyin
Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 6,8İstismar yokEPSS %2positive software · sitestudio16 May 2005
- CVE-2008-444827İzleyin
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perf
OrtaCVSS 6,8İstismar yokEPSS %1positive software · h-sphere6 Eki 2008
- CVE-2006-638227İzleyin
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which a
OrtaCVSS 6,8İstismar yokEPSS %0positive software · h-sphere7 Ara 2006
- CVE-2005-160618İzleyin
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, whi
OrtaCVSS 4,6Kavram kanıtıEPSS %1positive software · h-sphere winbox16 May 2005
- CVE-2008-444717İzleyin
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbi
OrtaCVSS 4,3Kavram kanıtıEPSS %1positive software · h-sphere6 Eki 2008
- CVE-2006-019317İzleyin
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and ear
OrtaCVSS 4,3İstismar yokEPSS %1positive software · h-sphere13 Oca 2006
- CVE-2006-327810İzleyin
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML
DüşükCVSS 2,6İstismar yokEPSS %1positive software · h-sphere28 Haz 2006