thinkadmin kayıtları
thinkadmin üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %22,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2020-25540Kavram kanıtı | ThinkAdmin v6 is affected by a directory traversal vulnerability.thinkadmin · thinkadmin · CWE-22 | Yüksek7,5 | — | %75,3 | 14 Eyl 2020 |
40Planlayın | CVE-2020-23653İstismar yok | An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wthinkadmin · thinkadmin · CWE-502 | Kritik9,8 | — | %4,1 | 13 Oca 2021 |
39İzleyin | CVE-2019-11018İstismar yok | application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials afterthinkadmin · thinkadmin · CWE-287 | Kritik9,8 | — | %1,4 | 8 Nis 2019 |
35İzleyin | CVE-2023-48966İstismar yok | An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary cthinkadmin · thinkadmin · CWE-434 | Yüksek8,8 | — | %1,1 | 4 Ara 2023 |
35İzleyin | CVE-2023-48965İstismar yok | An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to downloadthinkadmin · thinkadmin · CWE-434 | Yüksek8,8 | — | %0,9 | 4 Ara 2023 |
31İzleyin | CVE-2020-35296İstismar yok | ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.thinkadmin · thinkadmin · CWE-798 | Yüksek7,5 | — | %2,2 | 3 Mar 2021 |
24İzleyin | CVE-2023-34833İstismar yok | An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crthinkadmin · thinkadmin · CWE-434 | Orta6,1 | — | %0,5 | 15 Haz 2023 |
21İzleyin | CVE-2020-29315İstismar yok | ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.thinkadmin · thinkadmin · CWE-79 | Orta5,4 | — | %1,0 | 1 Ara 2020 |
9İzleyin | CVE-2024-10749İstismar yok | ThinkAdmin Plugs.php script deserializationthinkadmin · thinkadmin · CWE-502 | Düşük2,3 | — | %0,5 | 3 Kas 2024 |
- CVE-2020-2554053Planlayın
ThinkAdmin v6 is affected by a directory traversal vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %75thinkadmin · thinkadmin14 Eyl 2020
- CVE-2020-2365340Planlayın
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/w
KritikCVSS 9,8İstismar yokEPSS %4thinkadmin · thinkadmin13 Oca 2021
- CVE-2019-1101839İzleyin
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after
KritikCVSS 9,8İstismar yokEPSS %1thinkadmin · thinkadmin8 Nis 2019
- CVE-2023-4896635İzleyin
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary c
YüksekCVSS 8,8İstismar yokEPSS %1thinkadmin · thinkadmin4 Ara 2023
- CVE-2023-4896535İzleyin
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download
YüksekCVSS 8,8İstismar yokEPSS %1thinkadmin · thinkadmin4 Ara 2023
- CVE-2020-3529631İzleyin
ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.
YüksekCVSS 7,5İstismar yokEPSS %2thinkadmin · thinkadmin3 Mar 2021
- CVE-2023-3483324İzleyin
An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a cr
OrtaCVSS 6,1İstismar yokEPSS %1thinkadmin · thinkadmin15 Haz 2023
- CVE-2020-2931521İzleyin
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
OrtaCVSS 5,4İstismar yokEPSS %1thinkadmin · thinkadmin1 Ara 2020
- CVE-2024-107499İzleyin
ThinkAdmin Plugs.php script deserialization
DüşükCVSS 2,3İstismar yokEPSS %1thinkadmin · thinkadmin3 Kas 2024