xcloner kayıtları
xcloner üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2020-35948Kavram kanıtı | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.xcloner · xcloner · CWE-863 | Yüksek8,8 | — | %24,9 | 1 Oca 2021 |
35İzleyin | CVE-2020-35950İstismar yok | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress.xcloner · xcloner · CWE-352 | Yüksek8,8 | — | %0,9 | 1 Oca 2021 |
32İzleyin | CVE-2014-2579Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authenxcloner · xcloner · CWE-352 | Yüksek7,6 | — | %6,0 | 25 Nis 2014 |
31İzleyin | CVE-2014-2996Kavram kanıtı | XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbxcloner · xcloner · CWE-94 | Yüksek7,1 | — | %9,9 | 25 Nis 2014 |
28İzleyin | CVE-2014-8603Kavram kanıtı | cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code xcloner · xcloner · CWE-20 | Orta6,5 | — | %6,2 | 10 Haz 2015 |
28İzleyin | CVE-2014-2340Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authexcloner · xcloner · CWE-352 | Orta6,8 | — | %2,9 | 3 Nis 2014 |
27İzleyin | CVE-2015-4336İstismar yok | cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file coxcloner · xcloner · CWE-77 | Orta6,5 | — | %2,7 | 17 Haz 2015 |
27İzleyin | CVE-2015-4338İstismar yok | Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP codexcloner · xcloner · CWE-94 | Orta6,5 | — | %2,3 | 17 Haz 2015 |
27İzleyin | CVE-2020-13424Kavram kanıtı | The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.xcloner · xcloner | Orta6,5 | — | %1,7 | 23 May 2020 |
22İzleyin | CVE-2014-8604Kavram kanıtı | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panexcloner · xcloner · CWE-200 | Orta5,0 | — | %6,9 | 10 Haz 2015 |
22İzleyin | CVE-2014-8605Kavram kanıtı | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insxcloner · xcloner · CWE-264 | Orta5,0 | — | %6,9 | 10 Haz 2015 |
18İzleyin | CVE-2014-8606Kavram kanıtı | Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitxcloner · xcloner · CWE-22 | Orta4,0 | — | %6,0 | 10 Haz 2015 |
14İzleyin | CVE-2015-4337İstismar yok | Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary webxcloner · xcloner · CWE-79 | Düşük3,5 | — | %1,6 | 17 Haz 2015 |
8İzleyin | CVE-2014-8607Kavram kanıtı | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows locaxcloner · xcloner · CWE-200 | Düşük2,1 | — | %0,9 | 10 Haz 2015 |
- CVE-2020-3594842Planlayın
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.
YüksekCVSS 8,8Kavram kanıtıEPSS %25xcloner · xcloner1 Oca 2021
- CVE-2020-3595035İzleyin
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress.
YüksekCVSS 8,8İstismar yokEPSS %1xcloner · xcloner1 Oca 2021
- CVE-2014-257932İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authen
YüksekCVSS 7,6Kavram kanıtıEPSS %6xcloner · xcloner25 Nis 2014
- CVE-2014-299631İzleyin
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arb
YüksekCVSS 7,1Kavram kanıtıEPSS %10xcloner · xcloner25 Nis 2014
- CVE-2014-860328İzleyin
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code
OrtaCVSS 6,5Kavram kanıtıEPSS %6xcloner · xcloner10 Haz 2015
- CVE-2014-234028İzleyin
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authe
OrtaCVSS 6,8Kavram kanıtıEPSS %3xcloner · xcloner3 Nis 2014
- CVE-2015-433627İzleyin
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file co
OrtaCVSS 6,5İstismar yokEPSS %3xcloner · xcloner17 Haz 2015
- CVE-2015-433827İzleyin
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code
OrtaCVSS 6,5İstismar yokEPSS %2xcloner · xcloner17 Haz 2015
- CVE-2020-1342427İzleyin
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
OrtaCVSS 6,5Kavram kanıtıEPSS %2xcloner · xcloner23 May 2020
- CVE-2014-860422İzleyin
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration pane
OrtaCVSS 5,0Kavram kanıtıEPSS %7xcloner · xcloner10 Haz 2015
- CVE-2014-860522İzleyin
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with ins
OrtaCVSS 5,0Kavram kanıtıEPSS %7xcloner · xcloner10 Haz 2015
- CVE-2014-860618İzleyin
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbit
OrtaCVSS 4,0Kavram kanıtıEPSS %6xcloner · xcloner10 Haz 2015
- CVE-2015-433714İzleyin
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web
DüşükCVSS 3,5İstismar yokEPSS %2xcloner · xcloner17 Haz 2015
- CVE-2014-86078İzleyin
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows loca
DüşükCVSS 2,1Kavram kanıtıEPSS %1xcloner · xcloner10 Haz 2015