|
249261
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
|
CWE-74
Injection
|
CVE-2017-18387
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249262
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
|
CWE-74
Injection
|
CVE-2017-18386
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249263
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
|
CWE-284
Improper Access Control
|
CVE-2017-18385
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249264
|
3.8 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
|
CWE-284
Improper Access Control
|
CVE-2017-18384
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249265
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18383
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249266
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
|
CWE-20
Improper Input Validation
|
CVE-2017-18382
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249267
|
7.2 |
HIGH
Network
|
edx
|
edx-platform
|
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
|
NVD-CWE-noinfo
|
CVE-2017-18381
|
2024-11-21 12:19 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249268
|
7.5 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
|
CWE-284
Improper Access Control
|
CVE-2017-18380
|
2024-11-21 12:19 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249269
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18379
|
2024-11-21 12:19 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249270
|
9.8 |
CRITICAL
Network
|
web-gooroo
|
cms_web-gooroo
|
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18346
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|