Tobesoft
Tobesoft Xplatform: vulnerabilidades y CVE
Tobesoft Xplatform tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-26629 | Alta (8.8) | 1.6% | — | 26 abr 2022 | A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path… |
| CVE-2021-26626 | Alta (8.8) | 1.3% | — | 19 abr 2022 | Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be… |
| CVE-2020-7866 | Crítica (9.8) | 1.00% | — | 20 jul 2021 | When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation |
| CVE-2020-7857 | Crítica (9.8) | 1.0% | — | 20 abr 2021 | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of improper classes. This issue affects: Tobesoft XPlatform… |
| CVE-2020-7853 | Crítica (9.8) | 0.83% | — | 24 mar 2021 | An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker can exploit arbitrary code execution. |
| CVE-2020-7841 | Alta (8.8) | 1.6% | — | 17 nov 2020 | Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto:// |
| CVE-2020-7815 | Crítica (9.8) | 1.2% | — | 10 jul 2020 | XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download… |
| CVE-2019-19162 | Alta (7.8) | 1.2% | — | 11 may 2020 | A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it. |
| CVE-2020-7806 | Crítica (9.8) | 0.75% | — | 6 may 2020 | Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution. |
| CVE-2019-19166 | Alta (7.8) | 0.40% | — | 6 may 2020 | Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution. |
| CVE-2018-5197 | Alta (7.8) | 1.1% | — | 2 ene 2019 | A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input… |