|
251721
|
7.5 |
HIGH
Network
|
tiandy
|
tiandy_ip_camera_firmware
|
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config…
|
CWE-200
Information Exposure
|
CVE-2017-15236
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251722
|
7.5 |
HIGH
Network
|
horde
|
groupware
|
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact fi…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2017-15235
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251723
|
6.5 |
MEDIUM
Network
|
libjpeg-turbo
|
libjpeg-turbo
|
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15232
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251724
|
6.1 |
MEDIUM
Network
|
shaarli_project
|
shaarli
|
Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (fo…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15215
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251725
|
5.4 |
MEDIUM
Network
|
flyspray
|
flyspray
|
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript against other users (incl…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15214
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251726
|
5.4 |
MEDIUM
Network
|
flyspray
|
flyspray
|
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/temp…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15213
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251727
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.
|
CWE-200
Information Exposure
|
CVE-2017-15212
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251728
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15211
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251729
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.
|
CWE-200
Information Exposure
|
CVE-2017-15210
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251730
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15209
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|