Techno Portfolio Management Panel
by Techno Portfolio Management Panel Project
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17110 | Cri | 0.67 | 9.8 | 0.09 | Dec 11, 2017 | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. | ||
| CVE-2017-17695 | Hig | 0.57 | 8.8 | 0.01 | Dec 15, 2017 | Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter. | ||
| CVE-2017-17694 | Med | 0.35 | 5.4 | 0.01 | Dec 15, 2017 | Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter. | ||
| CVE-2017-17696 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2017 | Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php. | ||
| CVE-2017-17693 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2017 | Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback. |
- risk 0.67cvss 9.8epss 0.09
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
- risk 0.57cvss 8.8epss 0.01
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.
- risk 0.35cvss 5.4epss 0.01
Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter.
- risk 0.28cvss 4.3epss 0.01
Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php.
- risk 0.28cvss 4.3epss 0.01
Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.