|
251351
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant
|
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
|
CWE-362
Race Condition
|
CVE-2017-16001
|
2024-11-21 12:15 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251352
|
7.8 |
HIGH
Local
|
ignitum
|
sera
|
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-15918
|
2024-11-21 12:15 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251353
|
7.0 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
|
CWE-362
Race Condition
|
CVE-2017-15884
|
2024-11-21 12:15 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251354
|
7.8 |
HIGH
Local
|
flexense
|
syncbreeze
|
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destina…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15950
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251355
|
9.8 |
CRITICAL
Network
|
zomato_clone_script_project
|
zomato_clone_script
|
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15993
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251356
|
9.8 |
CRITICAL
Network
|
website_broker_script_project
|
website_broker_script
|
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
|
CWE-89
SQL Injection
|
CVE-2017-15992
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251357
|
9.8 |
CRITICAL
Network
|
vastal
|
agent_zone
|
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type,…
|
CWE-89
SQL Injection
|
CVE-2017-15991
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251358
|
9.8 |
CRITICAL
Network
|
savsofteproducts
|
phpinventory
|
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15990
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251359
|
9.8 |
CRITICAL
Network
|
online_exam_test_application_project
|
online_exam_test_application
|
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
|
CWE-89
SQL Injection
|
CVE-2017-15989
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251360
|
9.8 |
CRITICAL
Network
|
nicephpscripts
|
nice_php_faq_script
|
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
|
CWE-89
SQL Injection
|
CVE-2017-15988
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|