Btiteam
Btiteam Xbtit: vulnerabilidades y CVE
Btiteam Xbtit tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-45822 | Media (6.1) | 1.1% | — | 16 mar 2022 | A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this… |
| CVE-2021-45821 | Alta (8.8) | 2.7% | — | 16 mar 2022 | A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data… |
| CVE-2018-17870 | Media (6.1) | 0.80% | — | 1 oct 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683. |
| CVE-2018-16361 | Media (6.1) | 0.95% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter. |
| CVE-2018-15684 | Media (5.3) | 0.96% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead to full path disclosure and leakage of sensitive data. |
| CVE-2018-15683 | Media (6.1) | 0.70% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be… |
| CVE-2018-15682 | Alta (8.8) | 0.54% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page… |
| CVE-2018-15681 | Crítica (9.8) | 0.75% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and… |
| CVE-2018-15680 | Crítica (9.8) | 0.79% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values… |
| CVE-2018-15679 | Media (6.1) | 0.95% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting. |
| CVE-2018-15678 | Media (6.1) | 0.95% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting. |
| CVE-2018-15677 | Media (6.1) | 0.47% | — | 5 sept 2018 | The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF. |
| CVE-2018-15676 | Media (5.3) | 0.93% | — | 5 sept 2018 | An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php anti-XSS mechanism that looks for a number of dangerous fingerprints. |