|
249871
|
6.1 |
MEDIUM
Network
|
readymade_video_sharing_script_project
|
readymade_video_sharing_script
|
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
|
CWE-94
Code Injection
|
CVE-2017-17649
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249872
|
9.8 |
CRITICAL
Network
|
phpautoclassifiedscript
|
bus_booking_script
|
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
|
CWE-89
SQL Injection
|
CVE-2017-17645
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249873
|
9.8 |
CRITICAL
Network
|
lynda_clone_project
|
lynda_clone
|
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
|
CWE-89
SQL Injection
|
CVE-2017-17643
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249874
|
6.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17741
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249875
|
7.5 |
HIGH
Network
|
openldap opensuse oracle mcafee
|
openldap leap blockchain_platform policy_auditor
|
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows r…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17740
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249876
|
9.8 |
CRITICAL
Network
|
brightsign
|
4k242_firmware
|
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
|
CWE-22
Path Traversal
|
CVE-2017-17739
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249877
|
7.5 |
HIGH
Network
|
brightsign
|
4k242_firmware
|
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
|
NVD-CWE-noinfo
|
CVE-2017-17738
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249878
|
6.1 |
MEDIUM
Network
|
brightsign
|
4k242_firmware
|
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17737
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249879
|
9.8 |
CRITICAL
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
|
CWE-200
Information Exposure
|
CVE-2017-17735
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249880
|
9.8 |
CRITICAL
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
|
CWE-200
Information Exposure
|
CVE-2017-17734
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|