|
250011
|
9.8 |
CRITICAL
Network
|
expedia_clone_project
|
expedia_clone
|
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17570
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250012
|
6.1 |
MEDIUM
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17569
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250013
|
7.5 |
HIGH
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive inform…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-17568
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250014
|
7.5 |
HIGH
Network
|
scubez
|
posty_readymade_classifieds
|
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17567
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250015
|
7.5 |
HIGH
Network
|
mikrotik
|
router_firmware
|
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
|
NVD-CWE-noinfo
|
CVE-2017-17538
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250016
|
7.8 |
HIGH
Local
|
xen
|
xen
|
An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in shadow mode by mapping a certain auxiliary page.
|
NVD-CWE-noinfo
|
CVE-2017-17566
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250017
|
5.6 |
MEDIUM
Local
|
xen
|
xen
|
An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion …
|
CWE-20
Improper Input Validation
|
CVE-2017-17565
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250018
|
7.8 |
HIGH
Local
|
xen
|
xen
|
An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference count…
|
CWE-388
7PK - Errors
|
CVE-2017-17564
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250019
|
7.8 |
HIGH
Local
|
xen
|
xen
|
An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging an incorrect mask for reference-count overfl…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17563
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250020
|
7.2 |
HIGH
Network
|
seacms_project
|
seacms
|
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.
|
NVD-CWE-noinfo
|
CVE-2017-17561
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|