Clip-bucket
Clip-bucket Clipbucket: vulnerabilidades y CVE
Clip-bucket Clipbucket tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2013-10040 | Crítica (10) | 3.7% | — | 31 jul 2025 | ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files,… |
| CVE-2018-7666 | Crítica (9.8) | 1.3% | — | 5 mar 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the… |
| CVE-2018-7665 | Crítica (9.8) | 16% | — | 5 mar 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to… |
| CVE-2018-7664 | Crítica (9.8) | 2.0% | — | 5 mar 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php. |
| CVE-2016-1000307 | Media (6.1) | 0.75% | — | 6 abr 2017 | Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies,… |
| CVE-2015-4673 | Media (5.4) | 0.80% | — | 6 abr 2017 | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to… |
| CVE-2016-4848 | Media (6.1) | 1.6% | — | 2 sept 2016 | Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2012-5849 | Alta (7.5) | 2.8% | — | 14 may 2015 | Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in an add_friend action to ajax.php; id parameter in a… |
| CVE-2015-2102 | Alta (7.5) | 2.4% | — | 27 feb 2015 | SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter. |
| CVE-2014-4187 | Media (4.3) | 1.4% | — | 17 jun 2014 | Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web script or HTML via the Username field. |
| CVE-2012-6644 | Media (4.3) | 3.2% | — | 8 abr 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4)… |
| CVE-2012-6643 | Alta (7.5) | 1.5% | — | 8 abr 2014 | Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2)… |
| CVE-2012-6642 | Media (4.3) | 0.93% | — | 8 abr 2014 | Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the provenance of this information is unknown;… |
| CVE-2011-3717 | Media (5) | 1.3% | — | 23 sept 2011 | ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.