|
247621
|
5.5 |
MEDIUM
Local
|
unitrends
|
enterprise_backup
|
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This …
|
CWE-200
Information Exposure
|
CVE-2017-7282
|
2024-11-21 12:31 |
2017-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247622
|
9.1 |
CRITICAL
Network
|
atlassian
|
hipchat_server
|
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-7357
|
2024-11-21 12:31 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247623
|
5.4 |
MEDIUM
Network
|
zurmo
|
zurmo_crm
|
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7188
|
2024-11-21 12:31 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247624
|
5.0 |
MEDIUM
Local
|
moxa
|
mx-aopc_server
|
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
|
CWE-611
XXE
|
CVE-2017-7457
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247625
|
7.5 |
HIGH
Network
|
moxa
|
mxview
|
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
|
CWE-20
Improper Input Validation
|
CVE-2017-7456
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247626
|
7.5 |
HIGH
Network
|
moxa
|
mxview
|
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
|
CWE-200
Information Exposure
|
CVE-2017-7455
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247627
|
7.5 |
HIGH
Network
|
paloaltonetworks
|
traps
|
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
|
CWE-20
Improper Input Validation
|
CVE-2017-7408
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247628
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.
|
CWE-20
Improper Input Validation
|
CVE-2017-7218
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247629
|
4.3 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.
|
CWE-20
Improper Input Validation
|
CVE-2017-7217
|
2024-11-21 12:31 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247630
|
8.8 |
HIGH
Network
|
citrix
|
netscaler_gateway_firmware
|
A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7219
|
2024-11-21 12:31 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|