|
247361
|
9.8 |
CRITICAL
Network
|
xiongmaitech
|
uc-httpd
|
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
|
CWE-22
Path Traversal
|
CVE-2017-7577
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247362
|
8.8 |
HIGH
Network
|
pivotx
|
pivotx
|
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to ch…
|
CWE-94
Code Injection
|
CVE-2017-7570
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247363
|
9.8 |
CRITICAL
Network
|
dragonwavex
|
horizon_wireless_radio_firmware
|
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credent…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-7576
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247364
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_tm221ce16r_firmware
|
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x00\x05\x01\x5a\x00\x03\x00 request to the Modbus p…
|
CWE-200
Information Exposure
|
CVE-2017-7575
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247365
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_tm221ce16r_firmware somachine
|
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-7574
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247366
|
8.0 |
HIGH
Network
|
ladybirdweb
|
faveo_helpdesk
|
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
|
CWE-352
Origin Validation Error
|
CVE-2017-7571
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247367
|
8.6 |
HIGH
Network
|
vbulletin
|
vbulletin
|
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-7569
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247368
|
7.7 |
HIGH
Network
|
mybb
|
mybb
|
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-7566
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247369
|
8.8 |
HIGH
Network
|
splunk
|
hadoop_connect
|
Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.
|
CWE-22
Path Traversal
|
CVE-2017-7565
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247370
|
8.1 |
HIGH
Network
|
backintime_project
|
backintime
|
The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condi…
|
CWE-362
Race Condition
|
CVE-2017-7572
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|