Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 029

Количество 2 029

debian логотип

CVE-2021-33829

около 5 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
redhat логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2020-28949

больше 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Высокий
redhat логотип

CVE-2020-28949

больше 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.1
EPSS: Высокий
nvd логотип

CVE-2020-28949

больше 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Высокий
debian логотип

CVE-2020-28949

больше 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
EPSS: Высокий
ubuntu логотип

CVE-2020-28948

больше 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Средний
redhat логотип

CVE-2020-28948

больше 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Средний
nvd логотип

CVE-2020-28948

больше 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Средний
debian логотип

CVE-2020-28948

больше 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
EPSS: Средний
nvd логотип

CVE-2019-11876

около 7 лет назад

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10911

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10911

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10911

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10910

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-10910

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-10910

около 7 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor ...

CVSS3: 6.1
3%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
redhat логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
nvd логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
debian логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
ubuntu логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
85%
Высокий
больше 5 лет назад
redhat логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.1
85%
Высокий
больше 5 лет назад
nvd логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
85%
Высокий
больше 5 лет назад
debian логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
85%
Высокий
больше 5 лет назад
ubuntu логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
47%
Средний
больше 5 лет назад
redhat логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
47%
Средний
больше 5 лет назад
nvd логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
47%
Средний
больше 5 лет назад
debian логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
47%
Средний
больше 5 лет назад
nvd логотип
CVE-2019-11876

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.

CVSS3: 6.1
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 7.5
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
6%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
6%
Низкий
около 7 лет назад
debian логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 9.8
6%
Низкий
около 7 лет назад

Уязвимостей на страницу