İçeriğe atla
Noroxi

QiboSoft kayıtları

qibosoft üreticisine ait 14 yayımlanmış kayıt.

Tüm kayıtlar

14 kayıt
  • CVE-2019-17613
    40Planlayın

    qibosoft 7 allows remote code execution because do/jf.php makes eval calls.

    KritikCVSS 9,8İstismar yokEPSS %3

    qibosoft · qibosoft15 Eki 2019

  • CVE-2024-1225
    39İzleyin

    QiboSoft QiboCMS X1 Pay.php rmb_pay deserialization

    KritikCVSS 9,8İstismar yokEPSS %1

    qibosoft · qibocms x15 Şub 2024

  • CVE-2020-20944
    37İzleyin

    An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.

    KritikCVSS 9,1İstismar yokEPSS %2

    qibosoft · qibosoft27 Ara 2021

  • CVE-2023-27037
    35İzleyin

    Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php

    YüksekCVSS 8,8İstismar yokEPSS %1

    qibosoft · qibocms16 Mar 2023

  • CVE-2020-20945
    35İzleyin

    A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add admi

    YüksekCVSS 8,8İstismar yokEPSS %1

    qibosoft · qibosoft27 Ara 2021

  • CVE-2018-18201
    35İzleyin

    qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.

    YüksekCVSS 8,8İstismar yokEPSS %0

    qibosoft · qibosoft9 Eki 2018

  • CVE-2019-5725
    30İzleyin

    qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a UR

    YüksekCVSS 7,5İstismar yokEPSS %1

    qibosoft · qibosoft8 Oca 2019

  • CVE-2025-22973
    30İzleyin

    An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application

    YüksekCVSS 7,5İstismar yokEPSS %0

    qibosoft · qibocms x120 Şub 2025

  • CVE-2021-27811
    28İzleyin

    A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0.

    YüksekCVSS 7,2İstismar yokEPSS %1

    qibosoft · qibosoft21 May 2021

  • CVE-2011-1064
    27İzleyin

    SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aid

    OrtaCVSS 6,8İstismar yokEPSS %1

    qibosoft · qi bo cms22 Şub 2011

  • CVE-2020-18022
    24İzleyin

    Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive informat

    OrtaCVSS 6,1İstismar yokEPSS %1

    qibosoft · qibocms28 Nis 2021

  • CVE-2020-20808
    24İzleyin

    Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd a

    OrtaCVSS 6,1İstismar yokEPSS %1

    qibosoft · qibosoft2 Ağu 2023

  • CVE-2020-20946
    21İzleyin

    Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.

    OrtaCVSS 5,4İstismar yokEPSS %1

    qibosoft · qibosoft27 Ara 2021

  • CVE-2020-20943
    17İzleyin

    A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arb

    OrtaCVSS 4,3İstismar yokEPSS %0

    qibosoft · qibosoft27 Ara 2021