|
250001
|
6.1 |
MEDIUM
Network
|
communigate
|
communigate_pro
|
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16962
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250002
|
6.5 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application…
|
CWE-89
SQL Injection
|
CVE-2017-16961
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250003
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wvr300 tl-wvr302 tl-wvr450g tl-wvr900g tl-er5510g tl-er5520g tl-er6120g tl-er6520g tl-r473 tl-r478 tl-r478\+ tl-r478g\+ tl-r483 tl-r483g tl-r488 tl-r42…
|
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/…
|
CWE-78
OS Command
|
CVE-2017-16960
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250004
|
6.1 |
MEDIUM
Network
|
symphony_project
|
symphony
|
b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16956
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250005
|
8.8 |
HIGH
Network
|
inlinks_project
|
inlinks
|
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?p…
|
CWE-89
SQL Injection
|
CVE-2017-16955
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250006
|
6.5 |
MEDIUM
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;local…
|
CWE-22
Path Traversal
|
CVE-2017-16959
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250007
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luc…
|
CWE-78
OS Command
|
CVE-2017-16958
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250008
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/lu…
|
CWE-78
OS Command
|
CVE-2017-16957
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250009
|
7.8 |
HIGH
Local
|
tgsoft
|
vir.it_explorer
|
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730008 DeviceIoContr…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16948
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250010
|
4.9 |
MEDIUM
Network
|
misp
|
misp
|
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-16946
|
2024-11-21 12:17 |
2017-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|