pydio kayıtları
pydio üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %5,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-502 Deserialization of Untrusted Data3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2013-4267İstismar yok | Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter topydio · pydio · CWE-78 | Kritik9,8 | — | %4,1 | 11 Şub 2020 |
40Planlayın | CVE-2015-3431İstismar yok | Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Commanpydio · pydio · CWE-78 | Kritik9,8 | — | %4,1 | 19 Eyl 2017 |
40Planlayın | CVE-2018-20718Kavram kanıtı | In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to storepydio · pydio · CWE-502 | Kritik9,8 | — | %3,7 | 15 Oca 2019 |
40Planlayın | CVE-2019-9642İstismar yok | An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2.pydio · pydio · CWE-22 | Kritik9,8 | — | %2,4 | 5 Haz 2019 |
39İzleyin | CVE-2023-32749Kavram kanıtı | Pydio Cells allows users by default to create so-called external users in order to share files with them.pydio · cells · CWE-863 | Yüksek8,8 | — | %14,1 | 8 Haz 2023 |
36İzleyin | CVE-2019-20452İstismar yok | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.pydio · pydio · CWE-502 | Yüksek8,8 | — | %2,1 | 17 Mar 2020 |
36İzleyin | CVE-2019-20453İstismar yok | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.pydio · pydio · CWE-502 | Yüksek8,8 | — | %2,1 | 17 Mar 2020 |
35İzleyin | CVE-2019-12901İstismar yok | Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete filepydio · cells · CWE-22 | Yüksek8,8 | — | %1,7 | 19 Haz 2019 |
32İzleyin | CVE-2013-6227Kavram kanıtı | Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5ajaxplorer · ajaxplorer | Yüksek7,5 | — | %8,0 | 27 Ara 2014 |
32İzleyin | CVE-2020-12851İstismar yok | Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositoripydio · cells · CWE-22 | Yüksek8,1 | — | %1,5 | 4 Haz 2020 |
30İzleyin | CVE-2018-14772Kavram kanıtı | Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the webpydio · pydio · CWE-78 | Yüksek7,2 | — | %6,2 | 16 Eki 2018 |
30İzleyin | CVE-2019-15033İstismar yok | Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download.pydio · pydio · CWE-918 | Yüksek7,7 | — | %1,3 | 19 Eyl 2019 |
29İzleyin | CVE-2019-10048İstismar yok | The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of upydio · pydio · CWE-78 | Yüksek7,2 | — | %3,2 | 31 May 2019 |
29İzleyin | CVE-2020-12847İstismar yok | Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator ropydio · cells | Yüksek7,2 | — | %1,7 | 4 Haz 2020 |
29İzleyin | CVE-2019-10049İstismar yok | It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into oppydio · pydio · CWE-79 | Yüksek7,3 | — | %1,1 | 31 May 2019 |
28İzleyin | CVE-2020-12852İstismar yok | The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate thepydio · cells · CWE-20 | Orta6,8 | — | %2,4 | 4 Haz 2020 |
28İzleyin | CVE-2020-12850İstismar yok | The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4.pydio · cells · CWE-269 | Yüksek7,0 | — | %0,5 | 10 Haz 2020 |
27İzleyin | CVE-2023-32750Kavram kanıtı | Pydio Cells through 4.1.2 allows SSRF.pydio · cells · CWE-918 | Orta6,5 | — | %3,8 | 8 Haz 2023 |
27İzleyin | CVE-2018-1999018İstismar yok | Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antipydio · pydio · CWE-20 | Orta6,6 | — | %3,5 | 23 Tem 2018 |
27İzleyin | CVE-2021-41324İstismar yok | Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal filepydio · cells · CWE-22 | Orta6,5 | — | %2,1 | 30 Eyl 2021 |
27İzleyin | CVE-2021-41323İstismar yok | Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells filpydio · cells · CWE-22 | Orta6,5 | — | %2,1 | 30 Eyl 2021 |
26İzleyin | CVE-2021-41325İstismar yok | Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parametepydio · cells | Orta6,5 | — | %1,1 | 30 Eyl 2021 |
26İzleyin | CVE-2019-12902İstismar yok | Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion.pydio · cells · CWE-459 | Orta6,5 | — | %1,1 | 19 Haz 2019 |
26İzleyin | CVE-2019-10045İstismar yok | The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scrpydio · pydio · CWE-384 | Orta6,5 | — | %1,0 | 31 May 2019 |
24İzleyin | CVE-2018-1999016İstismar yok | Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inlinepydio · pydio · CWE-79 | Orta6,1 | — | %1,0 | 23 Tem 2018 |
- CVE-2013-426740Planlayın
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to
KritikCVSS 9,8İstismar yokEPSS %4pydio · pydio11 Şub 2020
- CVE-2015-343140Planlayın
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Comman
KritikCVSS 9,8İstismar yokEPSS %4pydio · pydio19 Eyl 2017
- CVE-2018-2071840Planlayın
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store
KritikCVSS 9,8Kavram kanıtıEPSS %4pydio · pydio15 Oca 2019
- CVE-2019-964240Planlayın
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2.
KritikCVSS 9,8İstismar yokEPSS %2pydio · pydio5 Haz 2019
- CVE-2023-3274939İzleyin
Pydio Cells allows users by default to create so-called external users in order to share files with them.
YüksekCVSS 8,8Kavram kanıtıEPSS %14pydio · cells8 Haz 2023
- CVE-2019-2045236İzleyin
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.
YüksekCVSS 8,8İstismar yokEPSS %2pydio · pydio17 Mar 2020
- CVE-2019-2045336İzleyin
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.
YüksekCVSS 8,8İstismar yokEPSS %2pydio · pydio17 Mar 2020
- CVE-2019-1290135İzleyin
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete file
YüksekCVSS 8,8İstismar yokEPSS %2pydio · cells19 Haz 2019
- CVE-2013-622732İzleyin
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5
YüksekCVSS 7,5Kavram kanıtıEPSS %8ajaxplorer · ajaxplorer27 Ara 2014
- CVE-2020-1285132İzleyin
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositori
YüksekCVSS 8,1İstismar yokEPSS %1pydio · cells4 Haz 2020
- CVE-2018-1477230İzleyin
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web
YüksekCVSS 7,2Kavram kanıtıEPSS %6pydio · pydio16 Eki 2018
- CVE-2019-1503330İzleyin
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download.
YüksekCVSS 7,7İstismar yokEPSS %1pydio · pydio19 Eyl 2019
- CVE-2019-1004829İzleyin
The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of u
YüksekCVSS 7,2İstismar yokEPSS %3pydio · pydio31 May 2019
- CVE-2020-1284729İzleyin
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator ro
YüksekCVSS 7,2İstismar yokEPSS %2pydio · cells4 Haz 2020
- CVE-2019-1004929İzleyin
It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into op
YüksekCVSS 7,3İstismar yokEPSS %1pydio · pydio31 May 2019
- CVE-2020-1285228İzleyin
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the
OrtaCVSS 6,8İstismar yokEPSS %2pydio · cells4 Haz 2020
- CVE-2020-1285028İzleyin
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4.
YüksekCVSS 7,0İstismar yokEPSS %0pydio · cells10 Haz 2020
- CVE-2023-3275027İzleyin
Pydio Cells through 4.1.2 allows SSRF.
OrtaCVSS 6,5Kavram kanıtıEPSS %4pydio · cells8 Haz 2023
- CVE-2018-199901827İzleyin
Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.anti
OrtaCVSS 6,6İstismar yokEPSS %3pydio · pydio23 Tem 2018
- CVE-2021-4132427İzleyin
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal file
OrtaCVSS 6,5İstismar yokEPSS %2pydio · cells30 Eyl 2021
- CVE-2021-4132327İzleyin
Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells fil
OrtaCVSS 6,5İstismar yokEPSS %2pydio · cells30 Eyl 2021
- CVE-2021-4132526İzleyin
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile paramete
OrtaCVSS 6,5İstismar yokEPSS %1pydio · cells30 Eyl 2021
- CVE-2019-1290226İzleyin
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion.
OrtaCVSS 6,5İstismar yokEPSS %1pydio · cells19 Haz 2019
- CVE-2019-1004526İzleyin
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scr
OrtaCVSS 6,5İstismar yokEPSS %1pydio · pydio31 May 2019
- CVE-2018-199901624İzleyin
Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline
OrtaCVSS 6,1İstismar yokEPSS %1pydio · pydio23 Tem 2018