|
252061
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14717
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252062
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14716
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252063
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14715
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252064
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14714
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252065
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14713
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252066
|
5.4 |
MEDIUM
Network
|
telaxius
|
epesi
|
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14712
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252067
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader
|
Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute arbitrary code or cause a denial of service via a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14694
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252068
|
9.8 |
CRITICAL
Network
|
denyall
|
web_application_firewall i-suite
|
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken …
|
CWE-287
Improper Authentication
|
CVE-2017-14706
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252069
|
8.1 |
HIGH
Network
|
denyall
|
web_application_firewall i-suite
|
DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webser…
|
CWE-78
OS Command
|
CVE-2017-14705
|
2024-11-21 12:13 |
2017-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252070
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selecti…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14693
|
2024-11-21 12:13 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|