|
251941
|
5.4 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14985
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251942
|
5.4 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the bp_name parameter to /m…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14984
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251943
|
4.8 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14983
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251944
|
5.4 |
MEDIUM
Network
|
atutor
|
atutor
|
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14981
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251945
|
7.5 |
HIGH
Network
|
gxlcms
|
gxlcms
|
Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, re…
|
NVD-CWE-noinfo
|
CVE-2017-14979
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251946
|
8.8 |
HIGH
Network
|
dasinfomedia
|
wphrm_human_resource_management_system
|
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14848
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251947
|
7.8 |
HIGH
Local
|
skyboxsecurity
|
skybox_manager_client_application
|
Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state. The vulnerability can only be …
|
NVD-CWE-noinfo
|
CVE-2017-14773
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251948
|
3.3 |
LOW
Local
|
skyboxsecurity
|
skybox_manager_client_application
|
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing…
|
CWE-200
Information Exposure
|
CVE-2017-14772
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251949
|
5.5 |
MEDIUM
Local
|
skyboxsecurity
|
skybox_manager_client_application
|
Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the app…
|
CWE-20
Improper Input Validation
|
CVE-2017-14771
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251950
|
5.5 |
MEDIUM
Local
|
skyboxsecurity
|
skybox_manager_client_application
|
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the password hashes in a debu…
|
CWE-200
Information Exposure
|
CVE-2017-14770
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|