|
248541
|
4.4 |
MEDIUM
Local
|
khoros
|
lithium_forum
|
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of th…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-20106
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248542
|
8.1 |
HIGH
Network
|
simplessus
|
simplessus
|
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2…
|
CWE-22
Path Traversal
|
CVE-2017-20105
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248543
|
7.5 |
HIGH
Network
|
simplessus
|
simplessus
|
A vulnerability was found in Simplessus 3.7.7. It has been declared as critical. This vulnerability affects unknown code of the component Cookie Handler. The manipulation of the argument UWA_SID lead…
|
CWE-89
SQL Injection
|
CVE-2017-20104
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248544
|
8.8 |
HIGH
Network
|
wp-kama
|
kama_click_counter
|
A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/…
|
CWE-89
SQL Injection
|
CVE-2017-20103
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248545
|
9.8 |
CRITICAL
Network
|
analytics_stats_counter_statistics_project
|
analytics_stats_counter_statistics
|
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The at…
|
CWE-94
Code Injection
|
CVE-2017-20099
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248546
|
4.8 |
MEDIUM
Network
|
weblizar
|
admin_custom_login
|
A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persisten…
|
CWE-79
Cross-site Scripting
|
CVE-2017-20098
|
2024-11-21 12:22 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248547
|
5.5 |
MEDIUM
Local
|
album_lock_project
|
album_lock
|
A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. The manipulation of the argument filePaht leads to …
|
CWE-22
Path Traversal
|
CVE-2017-20102
|
2024-11-21 12:22 |
2022-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248548
|
5.7 |
MEDIUM
Network
|
projectsend
|
projectsend
|
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-20101
|
2024-11-21 12:22 |
2022-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248549
|
6.1 |
MEDIUM
Network
|
air_transfer_project
|
air_transfer
|
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. T…
|
CWE-79
Cross-site Scripting
|
CVE-2017-20100
|
2024-11-21 12:22 |
2022-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248550
|
6.1 |
MEDIUM
Network
|
wp-filebase_download_manager_project
|
wp-filebase_download_manager
|
A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross s…
|
CWE-79
Cross-site Scripting
|
CVE-2017-20097
|
2024-11-21 12:22 |
2022-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|