status2k kayıtları
status2k üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-522 Insufficiently Protected Credentials1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2014-5091Kavram kanıtı | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malistatus2k · status2k · CWE-20 | Kritik9,8 | — | %15,2 | 7 Şub 2020 |
40Planlayın | CVE-2014-5093Kavram kanıtı | Status2k does not remove the install directory allowing credential reset.status2k · status2k · CWE-522 | Kritik9,8 | — | %3,8 | 10 Oca 2020 |
37İzleyin | CVE-2014-5092Kavram kanıtı | Status2k allows Remote Command Execution in admin/options/editpl.php.status2k · status2k · CWE-20 | Yüksek8,8 | — | %7,1 | 10 Oca 2020 |
30İzleyin | CVE-2014-5089Kavram kanıtı | SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commanstatus2k · status2k · CWE-89 | Yüksek7,5 | — | %1,2 | 6 Ağu 2014 |
27İzleyin | CVE-2014-5090Kavram kanıtı | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the status2k · status2k · CWE-94 | Orta6,5 | — | %2,8 | 6 Ağu 2014 |
22İzleyin | CVE-2014-5094Kavram kanıtı | Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the status2k · status2k · CWE-200 | Orta5,0 | — | %5,5 | 20 Eki 2014 |
17İzleyin | CVE-2014-5088Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to logistatus2k · status2k · CWE-79 | Orta4,3 | — | %1,5 | 6 Ağu 2014 |
- CVE-2014-509144Planlayın
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a mali
KritikCVSS 9,8Kavram kanıtıEPSS %15status2k · status2k7 Şub 2020
- CVE-2014-509340Planlayın
Status2k does not remove the install directory allowing credential reset.
KritikCVSS 9,8Kavram kanıtıEPSS %4status2k · status2k10 Oca 2020
- CVE-2014-509237İzleyin
Status2k allows Remote Command Execution in admin/options/editpl.php.
YüksekCVSS 8,8Kavram kanıtıEPSS %7status2k · status2k10 Oca 2020
- CVE-2014-508930İzleyin
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL comman
YüksekCVSS 7,5Kavram kanıtıEPSS %1status2k · status2k6 Ağu 2014
- CVE-2014-509027İzleyin
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the
OrtaCVSS 6,5Kavram kanıtıEPSS %3status2k · status2k6 Ağu 2014
- CVE-2014-509422İzleyin
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the
OrtaCVSS 5,0Kavram kanıtıEPSS %6status2k · status2k20 Eki 2014
- CVE-2014-508817İzleyin
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to logi
OrtaCVSS 4,3Kavram kanıtıEPSS %2status2k · status2k6 Ağu 2014