|
250981
|
9.8 |
CRITICAL
Network
|
django_make_app_project
|
django_make_app
|
An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulti…
|
NVD-CWE-noinfo
|
CVE-2017-16764
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250982
|
9.8 |
CRITICAL
Network
|
confire_project
|
confire
|
An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being loaded from "~/.confire.yaml" using the yaml.load fun…
|
NVD-CWE-noinfo
|
CVE-2017-16763
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250983
|
7.5 |
HIGH
Network
|
sanic_project
|
sanic
|
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
|
CWE-22
Path Traversal
|
CVE-2017-16762
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250984
|
6.1 |
MEDIUM
Network
|
inedo
|
buildmaster
|
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
|
CWE-601
Open Redirect
|
CVE-2017-16761
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250985
|
6.1 |
MEDIUM
Network
|
inedo
|
buildmaster
|
Inedo BuildMaster before 5.8.2 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16760
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250986
|
9.8 |
CRITICAL
Network
|
inedo
|
buildmaster
|
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
|
NVD-CWE-noinfo
|
CVE-2017-16521
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250987
|
5.3 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16754
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250988
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
|
CWE-287
Improper Authentication
|
CVE-2017-16634
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250989
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2017-16633
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250990
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16568
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|