|
265051
|
7.8 |
HIGH
Local
|
national_tax_agency
|
e-tax
|
Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2016-4901
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265052
|
7.8 |
HIGH
Local
|
evernote
|
evernote
|
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2016-4900
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265053
|
4.3 |
MEDIUM
Adjacent
|
toshiba
|
flashair
|
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series…
|
CWE-287
Improper Authentication
|
CVE-2016-4863
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265054
|
8.8 |
HIGH
Network
|
nttdocomo
|
l-04d_firmware
|
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary operations via unsp…
|
CWE-352
Origin Validation Error
|
CVE-2016-4854
|
2024-11-21 11:53 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265055
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4887
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265056
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4886
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265057
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4885
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265058
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4884
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265059
|
5.4 |
MEDIUM
Network
|
basercms
|
basercms
|
Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4883
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265060
|
8.8 |
HIGH
Network
|
basercms
|
basercms
|
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4882
|
2024-11-21 11:53 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|