|
248201
|
7.5 |
HIGH
Network
|
kubik-rubik
|
easy_joomla_backup
|
Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.
|
CWE-200
Information Exposure
|
CVE-2017-2550
|
2024-11-21 12:23 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248202
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
|
CWE-22
Path Traversal
|
CVE-2017-2258
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248203
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2257
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248204
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".
|
CWE-79
Cross-site Scripting
|
CVE-2017-2256
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248205
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
|
CWE-79
Cross-site Scripting
|
CVE-2017-2255
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248206
|
4.9 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
|
CWE-20
Improper Input Validation
|
CVE-2017-2254
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248207
|
7.8 |
HIGH
Local
|
ntt
|
flets_setsuzoku_tool
|
Untrusted search path vulnerability in Flets Setsuzoku Tool for Windows all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2017-2242
|
2024-11-21 12:23 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248208
|
7.8 |
HIGH
Local
|
kddi
|
qua_station_firmware
|
Untrusted search path vulnerability in Installer of Qua station connection tool for Windows version 1.00.03 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2017-2289
|
2024-11-21 12:23 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248209
|
7.8 |
HIGH
Local
|
enecho.meti
|
teikihoukokusho_sakuseishien_tool
|
Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2017-2228
|
2024-11-21 12:23 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248210
|
7.8 |
HIGH
Local
|
baidu
|
baidu_ime
|
Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2017-2221
|
2024-11-21 12:23 |
2017-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|