|
251211
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that trig…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15996
|
2024-11-21 12:15 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251212
|
9.8 |
CRITICAL
Network
|
samba
|
rsync
|
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has signi…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2017-15994
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251213
|
9.8 |
CRITICAL
Network
|
zeescripts
|
zeebuddy
|
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.
|
CWE-89
SQL Injection
|
CVE-2017-15976
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251214
|
9.8 |
CRITICAL
Network
|
vastal
|
dating_zone
|
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.
|
CWE-89
SQL Injection
|
CVE-2017-15975
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251215
|
9.8 |
CRITICAL
Network
|
datacomponents
|
tpanel
|
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
|
CWE-89
SQL Injection
|
CVE-2017-15974
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251216
|
9.8 |
CRITICAL
Network
|
sokial
|
sokial
|
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
|
CWE-89
SQL Injection
|
CVE-2017-15973
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251217
|
9.8 |
CRITICAL
Network
|
softdatepro
|
dating_software
|
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15…
|
CWE-89
SQL Injection
|
CVE-2017-15972
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251218
|
9.8 |
CRITICAL
Network
|
softdatepro
|
same_date_pro
|
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
|
CWE-89
SQL Injection
|
CVE-2017-15971
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251219
|
9.8 |
CRITICAL
Network
|
phpcityportal
|
phpcityportal
|
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15970
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251220
|
9.8 |
CRITICAL
Network
|
pilotgroup
|
allsharevideo
|
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
|
CWE-89
SQL Injection
|
CVE-2017-15969
|
2024-11-21 12:15 |
2017-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|