yxcms kayıtları
yxcms üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2018-8761İstismar yok | protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attyxcms · yxcms | Yüksek7,5 | — | %0,9 | 19 Mar 2018 |
28İzleyin | CVE-2018-19404İstismar yok | In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code byyxcms · yxcms · CWE-94 | Yüksek7,2 | — | %1,6 | 20 Kas 2018 |
26İzleyin | CVE-2018-11003İstismar yok | An issue was discovered in YXcms 1.4.7.yxcms · yxcms · CWE-352 | Orta6,5 | — | %0,7 | 12 May 2018 |
24İzleyin | CVE-2018-8805İstismar yok | Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\default\extend_guestboyxcms · yxcms · CWE-79 | Orta6,1 | — | %0,7 | 20 Mar 2018 |
19İzleyin | CVE-2018-13025İstismar yok | protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admyxcms · yxcms · CWE-732 | Orta4,9 | — | %0,8 | 29 Haz 2018 |
- CVE-2018-876130İzleyin
protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing att
YüksekCVSS 7,5İstismar yokEPSS %1yxcms · yxcms19 Mar 2018
- CVE-2018-1940428İzleyin
In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by
YüksekCVSS 7,2İstismar yokEPSS %2yxcms · yxcms20 Kas 2018
- CVE-2018-1100326İzleyin
An issue was discovered in YXcms 1.4.7.
OrtaCVSS 6,5İstismar yokEPSS %1yxcms · yxcms12 May 2018
- CVE-2018-880524İzleyin
Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\default\extend_guestbo
OrtaCVSS 6,1İstismar yokEPSS %1yxcms · yxcms20 Mar 2018
- CVE-2018-1302519İzleyin
protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=adm
OrtaCVSS 4,9İstismar yokEPSS %1yxcms · yxcms29 Haz 2018