|
255731
|
5.3 |
MEDIUM
Network
|
fullworks
|
stop_user_enumeration
|
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
|
CWE-200
Information Exposure
|
CVE-2017-1000226
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255732
|
6.1 |
MEDIUM
Network
|
relevanssi
|
relevanssi
|
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000225
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255733
|
5.4 |
MEDIUM
Network
|
modx
|
modx_revolution
|
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious Java…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000223
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255734
|
5.4 |
MEDIUM
Network
|
tine20
|
tine_2.0
|
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000164
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255735
|
5.4 |
MEDIUM
Network
|
expressionengine
|
expressionengine
|
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000160
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255736
|
9.8 |
CRITICAL
Network
|
python debian
|
python debian_linux
|
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code ex…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-1000158
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255737
|
7.5 |
HIGH
Network
|
s9y
|
serendipity
|
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
|
CWE-89
SQL Injection
|
CVE-2017-1000129
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255738
|
7.5 |
HIGH
Network
|
codiad
|
codiad
|
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-1000125
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255739
|
9.8 |
CRITICAL
Network
|
redis-store
|
redis-store
|
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-1000248
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255740
|
7.5 |
HIGH
Network
|
codeigniter
|
codeigniter
|
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
|
CWE-20
Improper Input Validation
|
CVE-2017-1000247
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|