Planet Estream
Vendor:
First CVE: Dec 25, 2022 · Active for 3 years
8
Total CVEs
More Total CVEs than 87% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Planet Estream over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2022
3 years ago
Most Recent CVE
Dec 25, 2022
1,311 days ago
CVE Severity & Scoring
Planet Estream8 CVEs
50%
25%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low4 (50.0%)
High1 (12.5%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45896CRITICAL Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/Process | Dec 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-45891CRITICAL Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.a | Dec 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-45889HIGH Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute a | Dec 25, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-45894MEDIUM GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files. | Dec 25, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-45893HIGH Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-for | Dec 25, 2022 | 8.8 | 22 | NO | NO |
CVE-2022-45890MEDIUM In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo pa | Dec 25, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-45892MEDIUM In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, | Dec 25, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-45895MEDIUM Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoin | Dec 25, 2022 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Planet Estream
Top CWEs
Versions
No cataloged versions.