|
247521
|
6.1 |
MEDIUM
Network
|
sanadata
|
sanacms
|
Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the txtFrom parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6518
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247522
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6511
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247523
|
6.1 |
MEDIUM
Network
|
burgundy-cms_project
|
burgundy-cms
|
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6509
|
2024-11-21 12:29 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247524
|
6.1 |
MEDIUM
Network
|
gnu
|
wget
|
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
|
CWE-93
CRLF Injection
|
CVE-2017-6508
|
2024-11-21 12:29 |
2017-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247525
|
8.8 |
HIGH
Network
|
dlink
|
dsl-2730u_firmware
|
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.
|
CWE-352
Origin Validation Error
|
CVE-2017-6411
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247526
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
|
CWE-20
Improper Input Validation
|
CVE-2017-6504
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247527
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6503
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247528
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6502
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247529
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6501
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247530
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6500
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|