|
249791
|
4.8 |
MEDIUM
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17985
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249792
|
4.8 |
MEDIUM
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17984
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249793
|
8.8 |
HIGH
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17983
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249794
|
6.8 |
MEDIUM
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
|
CWE-352
Origin Validation Error
|
CVE-2017-17982
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249795
|
5.4 |
MEDIUM
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17981
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249796
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a denial of service (system crash) or possibly have un…
|
CWE-416
Use After Free
|
CVE-2017-17975
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249797
|
9.8 |
CRITICAL
Network
|
basystems
|
bas920_firmware isc2000_firmware
|
BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_s…
|
NVD-CWE-noinfo
|
CVE-2017-17974
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249798
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
|
CWE-416
Use After Free
|
CVE-2017-17973
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249799
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17971
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249800
|
6.1 |
MEDIUM
Network
|
netwin
|
surgeftp
|
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17933
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|