|
249911
|
6.1 |
MEDIUM
Network
|
car_rental_script_project
|
car_rental_script
|
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17907
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249912
|
9.8 |
CRITICAL
Network
|
car_rental_script_project
|
car_rental_script
|
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17906
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249913
|
8.8 |
HIGH
Network
|
car_rental_script_project
|
car_rental_script
|
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
|
CWE-352
Origin Validation Error
|
CVE-2017-17905
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249914
|
5.4 |
MEDIUM
Network
|
fortunescripts
|
lynda_clone
|
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17904
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249915
|
8.8 |
HIGH
Network
|
fortunescripts
|
lynda_clone
|
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
|
CWE-352
Origin Validation Error
|
CVE-2017-17903
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249916
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17900
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249917
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17899
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249918
|
7.5 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2017-17898
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249919
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17897
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249920
|
6.1 |
MEDIUM
Network
|
basic_job_site_script_project
|
basic_job_site_script
|
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17896
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|