shopwind kayıtları
shopwind üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2022-30453İstismar yok | ShopWind <= 3.4.2 has a RCE vulnerability in Database.phpshopwind · shopwind | Kritik9,8 | — | %15,7 | 11 May 2022 |
32İzleyin | CVE-2024-1705İstismar yok | Shopwind Installation DefaultController.php actionCreate code injectionshopwind · shopwind · CWE-94 | Yüksek8,1 | — | %0,6 | 21 Şub 2024 |
28İzleyin | CVE-2022-30452İstismar yok | ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.phpshopwind · shopwind · CWE-89 | Yüksek7,2 | — | %1,0 | 11 May 2022 |
26İzleyin | CVE-2022-30059İstismar yok | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbControshopwind · shopwind · CWE-22 | Orta6,5 | — | %1,2 | 11 May 2022 |
24İzleyin | CVE-2022-43321İstismar yok | Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.shopwind · shopwind · CWE-79 | Orta6,1 | — | %0,4 | 9 Kas 2022 |
21İzleyin | CVE-2022-30058İstismar yok | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbContshopwind · shopwind · CWE-22 | Orta5,3 | — | %1,1 | 11 May 2022 |
21İzleyin | CVE-2022-30057İstismar yok | Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.shopwind · shopwind · CWE-79 | Orta5,4 | — | %0,5 | 11 May 2022 |
- CVE-2022-3045344Planlayın
ShopWind <= 3.4.2 has a RCE vulnerability in Database.php
KritikCVSS 9,8İstismar yokEPSS %16shopwind · shopwind11 May 2022
- CVE-2024-170532İzleyin
Shopwind Installation DefaultController.php actionCreate code injection
YüksekCVSS 8,1İstismar yokEPSS %1shopwind · shopwind21 Şub 2024
- CVE-2022-3045228İzleyin
ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php
YüksekCVSS 7,2İstismar yokEPSS %1shopwind · shopwind11 May 2022
- CVE-2022-3005926İzleyin
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbContro
OrtaCVSS 6,5İstismar yokEPSS %1shopwind · shopwind11 May 2022
- CVE-2022-4332124İzleyin
Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
OrtaCVSS 6,1İstismar yokEPSS %0shopwind · shopwind9 Kas 2022
- CVE-2022-3005821İzleyin
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbCont
OrtaCVSS 5,3İstismar yokEPSS %1shopwind · shopwind11 May 2022
- CVE-2022-3005721İzleyin
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.
OrtaCVSS 5,4İstismar yokEPSS %0shopwind · shopwind11 May 2022