|
253351
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15201
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253352
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15200
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253353
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15199
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253354
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
|
CWE-200
Information Exposure
|
CVE-2017-15198
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253355
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15197
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253356
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15196
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253357
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15195
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253358
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15194
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253359
|
4.8 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array par…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15188
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253360
|
9.8 |
CRITICAL
Network
|
zyxel
|
nbg6716_firmware
|
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.
|
CWE-78
OS Command
|
CVE-2017-15226
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|