services project kayıtları
services project üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2014-9152İstismar yok | The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accservices project · services · CWE-255 | Yüksek7,5 | — | %2,3 | 1 Ara 2014 |
30İzleyin | CVE-2014-9151İstismar yok | The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier foservices project · services · CWE-284 | Yüksek7,5 | — | %1,4 | 1 Ara 2014 |
27İzleyin | CVE-2013-2158İstismar yok | Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackersdrupal · drupal · CWE-352 | Orta6,8 | — | %0,7 | 1 Tem 2013 |
25İzleyin | CVE-2015-4393İstismar yok | The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with tservices project · services · CWE-20 | Orta6,0 | — | %1,7 | 15 Haz 2015 |
20İzleyin | CVE-2015-4394İstismar yok | The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive pservices project · services · CWE-264 | Orta5,0 | — | %1,4 | 15 Haz 2015 |
17İzleyin | CVE-2014-9153İstismar yok | Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to injeservices project · services · CWE-79 | Orta4,3 | — | %0,9 | 1 Ara 2014 |
- CVE-2014-915231İzleyin
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user acc
YüksekCVSS 7,5İstismar yokEPSS %2services project · services1 Ara 2014
- CVE-2014-915130İzleyin
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier fo
YüksekCVSS 7,5İstismar yokEPSS %1services project · services1 Ara 2014
- CVE-2013-215827İzleyin
Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers
OrtaCVSS 6,8İstismar yokEPSS %1drupal · drupal1 Tem 2013
- CVE-2015-439325İzleyin
The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with t
OrtaCVSS 6,0İstismar yokEPSS %2services project · services15 Haz 2015
- CVE-2015-439420İzleyin
The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive p
OrtaCVSS 5,0İstismar yokEPSS %1services project · services15 Haz 2015
- CVE-2014-915317İzleyin
Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inje
OrtaCVSS 4,3İstismar yokEPSS %1services project · services1 Ara 2014