|
250551
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
|
CWE-74
Injection
|
CVE-2017-18389
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250552
|
8.8 |
HIGH
Network
|
atlassian
|
data_center jira
|
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to ex…
|
CWE-94
Code Injection
|
CVE-2017-18113
|
2024-11-21 12:19 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250553
|
6.5 |
MEDIUM
Network
|
atlassian
|
fisheye
|
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are b…
|
CWE-200
Information Exposure
|
CVE-2017-18112
|
2024-11-21 12:19 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250554
|
5.9 |
MEDIUM
Network
|
bitcoin
|
bitcoin_core
|
bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server re…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-18350
|
2024-11-21 12:19 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250555
|
6.5 |
MEDIUM
Network
|
atlassian
|
crowd
|
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) …
|
CWE-352
Origin Validation Error
|
CVE-2017-18107
|
2024-11-21 12:19 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250556
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
|
CWE-20
Improper Input Validation
|
CVE-2017-18388
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250557
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
|
CWE-74
Injection
|
CVE-2017-18387
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250558
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
|
CWE-74
Injection
|
CVE-2017-18386
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250559
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
|
CWE-284
Improper Access Control
|
CVE-2017-18385
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250560
|
3.8 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
|
CWE-284
Improper Access Control
|
CVE-2017-18384
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|