Twentyone Degrees
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-3592 | 0.04 | — | 0.07 | Aug 11, 2008 | Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination… | |||
| CVE-2008-3591 | 0.03 | — | 0.02 | Aug 11, 2008 | SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php. | |||
| CVE-2024-23049 | 0.00 | — | 0.01 | Feb 5, 2024 | An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. | |||
| CVE-2019-17488 | 0.00 | — | 0.01 | Oct 10, 2019 | b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. | |||
| CVE-2018-16249 | 0.00 | — | 0.01 | Jun 20, 2019 | In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an… |
- CVE-2008-3592Aug 11, 2008risk 0.04cvss —epss 0.07
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination…
- CVE-2008-3591Aug 11, 2008risk 0.03cvss —epss 0.02
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.
- CVE-2024-23049Feb 5, 2024risk 0.00cvss —epss 0.01
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
- CVE-2019-17488Oct 10, 2019risk 0.00cvss —epss 0.01
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
- CVE-2018-16249Jun 20, 2019risk 0.00cvss —epss 0.01
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an…