speedtech kayıtları
speedtech üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2007-4738Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitraryspeedtech · stphplibrary · CWE-20 | Yüksek7,5 | — | %10,7 | 6 Eyl 2007 |
33İzleyin | CVE-2007-4737Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitraryspeedtech · stphplibrary · CWE-94 | Yüksek7,5 | — | %8,6 | 6 Eyl 2007 |
20İzleyin | CVE-2009-4515İstismar yok | The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attadrupal · drupal · CWE-264 | Orta5,0 | — | %1,3 | 31 Ara 2009 |
8İzleyin | CVE-2010-2123İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated usdrupal · drupal · CWE-79 | Düşük2,1 | — | %1,5 | 1 Haz 2010 |
8İzleyin | CVE-2010-2158İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated usdrupal · drupal · CWE-79 | Düşük2,1 | — | %0,7 | 7 Haz 2010 |
- CVE-2007-473833İzleyin
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %11speedtech · stphplibrary6 Eyl 2007
- CVE-2007-473733İzleyin
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %9speedtech · stphplibrary6 Eyl 2007
- CVE-2009-451520İzleyin
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote atta
OrtaCVSS 5,0İstismar yokEPSS %1drupal · drupal31 Ara 2009
- CVE-2010-21238İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated us
DüşükCVSS 2,1İstismar yokEPSS %2drupal · drupal1 Haz 2010
- CVE-2010-21588İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated us
DüşükCVSS 2,1İstismar yokEPSS %1drupal · drupal7 Haz 2010