Zikula kayıtları
zikula üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-310 Cryptographic Issues1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-2293İstismar yok | Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary filezikula · zikula application framework · CWE-94 | Kritik9,8 | — | %4,7 | 26 Mar 2018 |
40Planlayın | CVE-2016-9835İstismar yok | Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attackezikula · zikula application framework · CWE-77 | Kritik9,8 | — | %3,9 | 5 Ara 2016 |
27İzleyin | CVE-2011-0535Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authenticatzikula · zikula application framework · CWE-352 | Orta6,8 | — | %1,4 | 8 Şub 2011 |
27İzleyin | CVE-2010-4729İstismar yok | Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes itzikula · zikula application framework · CWE-352 | Orta6,8 | — | %0,5 | 8 Şub 2011 |
27İzleyin | CVE-2010-1732İstismar yok | Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to zikula · zikula application framework · CWE-352 | Orta6,8 | — | %0,5 | 6 May 2010 |
20İzleyin | CVE-2011-3826İstismar yok | Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation patzikula · zikula · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
20İzleyin | CVE-2010-4728İstismar yok | Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeatzikula · zikula application framework · CWE-310 | Orta5,0 | — | %0,9 | 8 Şub 2011 |
18İzleyin | CVE-2011-3979Kavram kanıtı | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Applicationzikula · zikula application framework · CWE-79 | Orta4,3 | — | %4,2 | 4 Eki 2011 |
18İzleyin | CVE-2010-1724Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to izikula · zikula application framework · CWE-79 | Orta4,3 | — | %4,1 | 6 May 2010 |
17İzleyin | CVE-2013-6168İstismar yok | Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web scriptzikula · zikula application framework · CWE-79 | Orta4,3 | — | %1,2 | 14 Kas 2013 |
17İzleyin | CVE-2011-0911İstismar yok | Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script ozikula · zikula application framework · CWE-79 | Orta4,3 | — | %0,9 | 8 Şub 2011 |
- CVE-2014-229340Planlayın
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary file
KritikCVSS 9,8İstismar yokEPSS %5zikula · zikula application framework26 Mar 2018
- CVE-2016-983540Planlayın
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacke
KritikCVSS 9,8İstismar yokEPSS %4zikula · zikula application framework5 Ara 2016
- CVE-2011-053527İzleyin
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authenticat
OrtaCVSS 6,8Kavram kanıtıEPSS %1zikula · zikula application framework8 Şub 2011
- CVE-2010-472927İzleyin
Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it
OrtaCVSS 6,8İstismar yokEPSS %1zikula · zikula application framework8 Şub 2011
- CVE-2010-173227İzleyin
Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to
OrtaCVSS 6,8İstismar yokEPSS %1zikula · zikula application framework6 May 2010
- CVE-2011-382620İzleyin
Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat
OrtaCVSS 5,0İstismar yokEPSS %1zikula · zikula23 Eyl 2011
- CVE-2010-472820İzleyin
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat
OrtaCVSS 5,0İstismar yokEPSS %1zikula · zikula application framework8 Şub 2011
- CVE-2011-397918İzleyin
Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application
OrtaCVSS 4,3Kavram kanıtıEPSS %4zikula · zikula application framework4 Eki 2011
- CVE-2010-172418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to i
OrtaCVSS 4,3Kavram kanıtıEPSS %4zikula · zikula application framework6 May 2010
- CVE-2013-616817İzleyin
Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1zikula · zikula application framework14 Kas 2013
- CVE-2011-091117İzleyin
Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script o
OrtaCVSS 4,3İstismar yokEPSS %1zikula · zikula application framework8 Şub 2011