|
251771
|
6.1 |
MEDIUM
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15648
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251772
|
7.5 |
HIGH
Network
|
fiberhome
|
routerfiberhome_firmware
|
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
|
CWE-22
Path Traversal
|
CVE-2017-15647
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251773
|
6.1 |
MEDIUM
Network
|
webmin
|
webmin
|
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After set…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15646
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251774
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
|
CWE-352
Origin Validation Error
|
CVE-2017-15645
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251775
|
8.6 |
HIGH
Network
|
webmin
|
webmin
|
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-15644
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251776
|
7.4 |
HIGH
Local
|
ikarussecurity
|
ikarus_antivirus
|
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleartext HTTP for updates along with a CRC32 checksum …
|
CWE-444
HTTP Request Smuggling
|
CVE-2017-15643
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251777
|
5.5 |
MEDIUM
Local
|
sound_exchange_project debian
|
sound_exchange debian_linux
|
In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
|
CWE-416
Use After Free
|
CVE-2017-15642
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251778
|
6.5 |
MEDIUM
Network
|
getmura
|
mura_cms
|
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
|
CWE-611
XXE
|
CVE-2017-15639
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251779
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15612
|
2024-11-21 12:14 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251780
|
6.5 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-15611
|
2024-11-21 12:14 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|