squiz kayıtları
squiz üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-502 Deserialization of Untrusted Data1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2019-19374İstismar yok | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Msquiz · matrix · CWE-22 | Kritik9,1 | — | %3,4 | 11 Ara 2019 |
36İzleyin | CVE-2017-14198İstismar yok | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3.squiz · matrix · CWE-94 | Yüksek8,8 | — | %1,8 | 29 Kas 2017 |
31İzleyin | CVE-2019-19373İstismar yok | An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3squiz · matrix · CWE-502 | Yüksek7,5 | — | %4,8 | 11 Ara 2019 |
31İzleyin | CVE-2017-14196İstismar yok | An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3.squiz · matrix · CWE-22 | Yüksek7,5 | — | %2,2 | 29 Kas 2017 |
27İzleyin | CVE-2006-5036İstismar yok | MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_psquiz · mysource classic | Orta6,8 | — | %1,3 | 27 Eyl 2006 |
27İzleyin | CVE-2006-5037İstismar yok | MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_srsquiz · mysource matrix | Orta6,8 | — | %1,3 | 27 Eyl 2006 |
26İzleyin | CVE-2006-4635İstismar yok | Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, tosquiz · mysource classic | Orta6,5 | — | %1,3 | 8 Eyl 2006 |
24İzleyin | CVE-2017-14197İstismar yok | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3.squiz · matrix · CWE-79 | Orta6,1 | — | %0,6 | 29 Kas 2017 |
21İzleyin | CVE-2022-32277İstismar yok | Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitsquiz · matrix · CWE-639 | Orta5,3 | — | %0,6 | 6 Eyl 2022 |
18İzleyin | CVE-2010-4901Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary websquiz · mysource matrix · CWE-79 | Orta4,3 | — | %1,7 | 8 Eki 2011 |
- CVE-2019-1937437İzleyin
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz M
KritikCVSS 9,1İstismar yokEPSS %3squiz · matrix11 Ara 2019
- CVE-2017-1419836İzleyin
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3.
YüksekCVSS 8,8İstismar yokEPSS %2squiz · matrix29 Kas 2017
- CVE-2019-1937331İzleyin
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3
YüksekCVSS 7,5İstismar yokEPSS %5squiz · matrix11 Ara 2019
- CVE-2017-1419631İzleyin
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3.
YüksekCVSS 7,5İstismar yokEPSS %2squiz · matrix29 Kas 2017
- CVE-2006-503627İzleyin
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_p
OrtaCVSS 6,8İstismar yokEPSS %1squiz · mysource classic27 Eyl 2006
- CVE-2006-503727İzleyin
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_sr
OrtaCVSS 6,8İstismar yokEPSS %1squiz · mysource matrix27 Eyl 2006
- CVE-2006-463526İzleyin
Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to
OrtaCVSS 6,5İstismar yokEPSS %1squiz · mysource classic8 Eyl 2006
- CVE-2017-1419724İzleyin
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3.
OrtaCVSS 6,1İstismar yokEPSS %1squiz · matrix29 Kas 2017
- CVE-2022-3227721İzleyin
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submit
OrtaCVSS 5,3İstismar yokEPSS %1squiz · matrix6 Eyl 2022
- CVE-2010-490118İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2squiz · mysource matrix8 Eki 2011