|
250021
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17782
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250022
|
9.8 |
CRITICAL
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17779
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250023
|
4.8 |
MEDIUM
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17778
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250024
|
9.8 |
CRITICAL
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.
|
CWE-287
Improper Authentication
|
CVE-2017-17777
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250025
|
5.3 |
MEDIUM
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
|
CWE-200
Information Exposure
|
CVE-2017-17776
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250026
|
6.1 |
MEDIUM
Network
|
piwigo
|
piwigo
|
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17775
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250027
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
admin/configuration.php in Piwigo 2.9.2 has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2017-17774
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250028
|
6.1 |
MEDIUM
Network
|
mediaburst
|
booking_calendar_sms clockwork_sms_notfications contact_form_7_sms fast_secure_contact_form_sms formidable gravity_forms two-factor_authentication wp_e-commerce
|
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following Wo…
|
CWE-79
Cross-site Scripting
|
CVE-2017-17780
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250029
|
7.5 |
HIGH
Network
|
liveqos
|
superbeam
|
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to sen…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-17763
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250030
|
9.8 |
CRITICAL
Network
|
ichano
|
athome_ip_camera_firmware
|
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. Th…
|
NVD-CWE-noinfo
|
CVE-2017-17761
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|