|
247641
|
6.1 |
MEDIUM
Network
|
webpagetest_project
|
webpagetest
|
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (benchmark) passed to the webpagetest-master/www/be…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6533
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247642
|
6.1 |
MEDIUM
Network
|
sanadata
|
sanacms
|
Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the txtFrom parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6518
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247643
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6511
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247644
|
6.1 |
MEDIUM
Network
|
burgundy-cms_project
|
burgundy-cms
|
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6509
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247645
|
6.1 |
MEDIUM
Network
|
gnu
|
wget
|
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
|
CWE-93
CRLF Injection
|
CVE-2017-6508
|
2024-11-21 12:29 |
2017-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247646
|
8.8 |
HIGH
Network
|
dlink
|
dsl-2730u_firmware
|
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.
|
CWE-352
Origin Validation Error
|
CVE-2017-6411
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247647
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
|
CWE-20
Improper Input Validation
|
CVE-2017-6504
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247648
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6503
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247649
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6502
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247650
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6501
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|