std42 kayıtları
std42 üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %12,5
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2019-9194Silahlaştırılmış | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.std42 · elfinder · CWE-78 | Kritik9,8 | — | %96,7 | 26 Şub 2019 |
60Bu hafta | CVE-2021-32682Silahlaştırılmış | Multiple vulnerabilities leading to RCEstd42 · elfinder · CWE-22 | Kritik9,8 | — | %69,9 | 14 Haz 2021 |
52Planlayın | CVE-2021-43421Kavram kanıtı | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to std42 · elfinder · CWE-434 | Kritik9,8 | — | %42,8 | 7 Nis 2022 |
51Planlayın | CVE-2022-26960Kavram kanıtı | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.std42 · elfinder · CWE-22 | Kritik9,1 | — | %51,0 | 21 Mar 2022 |
48Planlayın | CVE-2022-27115İstismar yok | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.std42 · elfinder · CWE-434 | Kritik9,8 | — | %28,6 | 11 Nis 2022 |
45Planlayın | CVE-2021-23394Kavram kanıtı | Remote Code Execution (RCE)std42 · elfinder · CWE-434 | Kritik9,8 | — | %18,9 | 13 Haz 2021 |
39İzleyin | CVE-2023-52044İstismar yok | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensistd42 · elfinder · CWE-434 | Kritik9,8 | — | %0,8 | 31 Eki 2024 |
39İzleyin | CVE-2024-38909İstismar yok | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.std42 · elfinder · CWE-284 | Kritik9,8 | — | %0,5 | 30 Tem 2024 |
37İzleyin | CVE-2018-9109İstismar yok | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Kritik9,1 | — | %2,9 | 28 Mar 2018 |
37İzleyin | CVE-2018-9110İstismar yok | Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Kritik9,1 | — | %2,9 | 28 Mar 2018 |
36İzleyin | CVE-2026-41247İstismar yok | elFinder: Command injection in resize background color parameter when using ImageMagick CLIstd42 · elfinder · CWE-78 | Yüksek8,9 | — | %2,7 | 23 Nis 2026 |
30İzleyin | CVE-2019-6257İstismar yok | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal std42 · elfinder · CWE-918 | Yüksek7,7 | — | %1,1 | 14 Oca 2019 |
27İzleyin | CVE-2023-35840Kavram kanıtı | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.std42 · elfinder · CWE-22 | Orta6,5 | — | %1,9 | 18 Haz 2023 |
24İzleyin | CVE-2023-52045İstismar yok | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.std42 · elfinder · CWE-79 | Orta6,1 | — | %0,3 | 31 Eki 2024 |
23İzleyin | CVE-2019-5884İstismar yok | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not sstd42 · elfinder · CWE-200 | Orta5,9 | — | %1,3 | 10 Oca 2019 |
21İzleyin | CVE-2021-45919İstismar yok | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.std42 · elfinder · CWE-79 | Orta5,4 | — | %0,6 | 8 Şub 2022 |
- CVE-2019-919468Bu hafta
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
KritikCVSS 9,8SilahlaştırılmışEPSS %97std42 · elfinder26 Şub 2019
- CVE-2021-3268260Bu hafta
Multiple vulnerabilities leading to RCE
KritikCVSS 9,8SilahlaştırılmışEPSS %70std42 · elfinder14 Haz 2021
- CVE-2021-4342152Planlayın
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to
KritikCVSS 9,8Kavram kanıtıEPSS %43std42 · elfinder7 Nis 2022
- CVE-2022-2696051Planlayın
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.
KritikCVSS 9,1Kavram kanıtıEPSS %51std42 · elfinder21 Mar 2022
- CVE-2022-2711548Planlayın
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
KritikCVSS 9,8İstismar yokEPSS %29std42 · elfinder11 Nis 2022
- CVE-2021-2339445Planlayın
Remote Code Execution (RCE)
KritikCVSS 9,8Kavram kanıtıEPSS %19std42 · elfinder13 Haz 2021
- CVE-2023-5204439İzleyin
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensi
KritikCVSS 9,8İstismar yokEPSS %1std42 · elfinder31 Eki 2024
- CVE-2024-3890939İzleyin
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.
KritikCVSS 9,8İstismar yokEPSS %0std42 · elfinder30 Tem 2024
- CVE-2018-910937İzleyin
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
KritikCVSS 9,1İstismar yokEPSS %3std42 · elfinder28 Mar 2018
- CVE-2018-911037İzleyin
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
KritikCVSS 9,1İstismar yokEPSS %3std42 · elfinder28 Mar 2018
- CVE-2026-4124736İzleyin
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
YüksekCVSS 8,9İstismar yokEPSS %3std42 · elfinder23 Nis 2026
- CVE-2019-625730İzleyin
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal
YüksekCVSS 7,7İstismar yokEPSS %1std42 · elfinder14 Oca 2019
- CVE-2023-3584027İzleyin
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
OrtaCVSS 6,5Kavram kanıtıEPSS %2std42 · elfinder18 Haz 2023
- CVE-2023-5204524İzleyin
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %0std42 · elfinder31 Eki 2024
- CVE-2019-588423İzleyin
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not s
OrtaCVSS 5,9İstismar yokEPSS %1std42 · elfinder10 Oca 2019
- CVE-2021-4591921İzleyin
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
OrtaCVSS 5,4İstismar yokEPSS %1std42 · elfinder8 Şub 2022