|
253111
|
7.5 |
HIGH
Network
|
oxid-esales
|
eshop
|
OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2017-14993
|
2024-11-21 12:13 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253112
|
6.5 |
MEDIUM
Network
|
netfortris
|
trixbox
|
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
|
CWE-22
Path Traversal
|
CVE-2017-14537
|
2024-11-21 12:13 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253113
|
5.4 |
MEDIUM
Network
|
netfortris
|
trixbox
|
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14536
|
2024-11-21 12:13 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253114
|
8.8 |
HIGH
Network
|
netfortris
|
trixbox
|
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
|
CWE-78
OS Command
|
CVE-2017-14535
|
2024-11-21 12:13 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253115
|
6.5 |
MEDIUM
Network
|
asus
|
dsl-ac51_firmware dsl-ac52u_firmware dsl-ac55u_firmware dsl-n55u_c1_firmware dsl-n55u_d1_firmware dsl-ac56u_firmware dsl-n10_c1_firmware dsl-n12u_c1_firmware dsl-n12e_c1_firmw…
|
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, …
|
CWE-611
XXE
|
CVE-2017-14699
|
2024-11-21 12:13 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253116
|
9.8 |
CRITICAL
Network
|
asus
|
dsl-ac51_firmware dsl-ac52u_firmware dsl-ac55u_firmware dsl-n55u_c1_firmware dsl-n55u_d1_firmware dsl-ac56u_firmware dsl-n10_c1_firmware dsl-n12u_c1_firmware dsl-n12e_c1_firmw…
|
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers all…
|
CWE-287
Improper Authentication
|
CVE-2017-14698
|
2024-11-21 12:13 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253117
|
8.8 |
HIGH
Network
|
atlassian
|
sourcetree
|
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows…
|
NVD-CWE-noinfo CWE-77
Command Injection
|
CVE-2017-14593
|
2024-11-21 12:13 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253118
|
8.8 |
HIGH
Network
|
atlassian
|
sourcetree
|
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is …
|
NVD-CWE-noinfo CWE-77
Command Injection
|
CVE-2017-14592
|
2024-11-21 12:13 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253119
|
9.8 |
CRITICAL
Network
|
netiq
|
access_manager
|
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrar…
|
NVD-CWE-noinfo
|
CVE-2017-14803
|
2024-11-21 12:13 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253120
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site …
|
CWE-79
Cross-site Scripting
|
CVE-2017-14594
|
2024-11-21 12:13 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|