|
249431
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
|
CWE-284
Improper Access Control
|
CVE-2017-18385
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249432
|
3.8 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
|
CWE-284
Improper Access Control
|
CVE-2017-18384
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249433
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18383
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249434
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
|
CWE-20
Improper Input Validation
|
CVE-2017-18382
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249435
|
7.2 |
HIGH
Network
|
edx
|
edx-platform
|
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
|
NVD-CWE-noinfo
|
CVE-2017-18381
|
2024-11-21 12:19 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249436
|
7.5 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
|
CWE-284
Improper Access Control
|
CVE-2017-18380
|
2024-11-21 12:19 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249437
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18379
|
2024-11-21 12:19 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249438
|
9.8 |
CRITICAL
Network
|
web-gooroo
|
cms_web-gooroo
|
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18346
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249439
|
6.1 |
MEDIUM
Network
|
archon_project
|
archon
|
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17972
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249440
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17945
|
2024-11-21 12:19 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|