Webedition kayıtları
webedition üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-2302İstismar yok | The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attwebedition · webedition cms · CWE-94 | Kritik9,8 | — | %4,5 | 19 Tem 2018 |
34İzleyin | CVE-2023-53883İstismar yok | Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creationwebedition · webedition cms · CWE-94 | Yüksek8,6 | — | %1,0 | 15 Ara 2025 |
31İzleyin | CVE-2014-2303Kavram kanıtı | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8webedition · webedition cms · CWE-89 | Yüksek7,5 | — | %2,6 | 13 Haz 2014 |
26İzleyin | CVE-2024-28418İstismar yok | Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.phpwebedition · webedition cms · CWE-434 | Orta6,5 | — | %0,4 | 14 Mar 2024 |
25İzleyin | CVE-2024-28417İstismar yok | Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.webedition · webedition cms · CWE-80 | Orta6,3 | — | %0,3 | 14 Mar 2024 |
22İzleyin | CVE-2014-5258Kavram kanıtı | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrwebedition · webedition cms · CWE-22 | Orta4,0 | — | %20,3 | 6 Kas 2014 |
21İzleyin | CVE-2009-1222Kavram kanıtı | Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is dwebedition · webedition · CWE-22 | Orta5,1 | — | %2,0 | 2 Nis 2009 |
20İzleyin | CVE-2023-53884İstismar yok | Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Uploadwebedition · webedition cms · CWE-79 | Orta5,1 | — | %0,3 | 15 Ara 2025 |
- CVE-2014-230240Planlayın
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection att
KritikCVSS 9,8İstismar yokEPSS %4webedition · webedition cms19 Tem 2018
- CVE-2023-5388334İzleyin
Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation
YüksekCVSS 8,6İstismar yokEPSS %1webedition · webedition cms15 Ara 2025
- CVE-2014-230331İzleyin
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8
YüksekCVSS 7,5Kavram kanıtıEPSS %3webedition · webedition cms13 Haz 2014
- CVE-2024-2841826İzleyin
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
OrtaCVSS 6,5İstismar yokEPSS %0webedition · webedition cms14 Mar 2024
- CVE-2024-2841725İzleyin
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
OrtaCVSS 6,3İstismar yokEPSS %0webedition · webedition cms14 Mar 2024
- CVE-2014-525822İzleyin
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitr
OrtaCVSS 4,0Kavram kanıtıEPSS %20webedition · webedition cms6 Kas 2014
- CVE-2009-122221İzleyin
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is d
OrtaCVSS 5,1Kavram kanıtıEPSS %2webedition · webedition2 Nis 2009
- CVE-2023-5388420İzleyin
Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Upload
OrtaCVSS 5,1İstismar yokEPSS %0webedition · webedition cms15 Ara 2025