|
247691
|
6.1 |
MEDIUM
Network
|
lucidcrew
|
pixie
|
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7360
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247692
|
6.1 |
MEDIUM
Network
|
lucidcrew
|
pixie
|
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7359
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247693
|
4.8 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a cra…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7309
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247694
|
4.8 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 't…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7241
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247695
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denia…
|
CWE-20
Improper Input Validation
|
CVE-2017-7346
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247696
|
8.8 |
HIGH
Network
|
dahuasecurity
|
ip_camera_firmware
|
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with ad…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2017-7253
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247697
|
9.8 |
CRITICAL
Network
|
modx
|
modx_revolution
|
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
|
CWE-94
Code Injection
|
CVE-2017-7324
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247698
|
8.1 |
HIGH
Network
|
modx
|
modx_revolution
|
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger…
|
NVD-CWE-noinfo
|
CVE-2017-7323
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247699
|
8.1 |
HIGH
Network
|
modx
|
modx_revolution
|
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serve…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-7322
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247700
|
9.8 |
CRITICAL
Network
|
modx
|
modx_revolution
|
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
|
CWE-94
Code Injection
|
CVE-2017-7321
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|