Known Vulnerabilities for products from Eprints
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Eprints".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-26704 json | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/... | 8.8 - HIGH | 2021-03-01 | 2021-03-04 |
| CVE-2021-26703 json | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a c... | 9.8 - CRITICAL | 2021-03-01 | 2021-03-04 |
| CVE-2021-26702 json | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI. | 6.1 - MEDIUM | 2021-03-01 | 2021-03-04 |
| CVE-2021-26476 json | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | 9.8 - CRITICAL | 2021-03-01 | 2021-03-04 |
| CVE-2021-26475 json | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. | 6.1 - MEDIUM | 2021-03-01 | 2021-03-04 |
| CVE-2021-3342 json | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/... | 9.8 - CRITICAL | 2021-03-01 | 2021-03-04 |
Known software with vulnerabilities from Eprints
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Eprints | Eprints | 3.1.0 |