|
255031
|
7.8 |
HIGH
Local
|
360totalsecurity
|
360_total_security
|
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-12653
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255032
|
8.8 |
HIGH
Network
|
loginizer
|
loginizer
|
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
|
CWE-352
Origin Validation Error
|
CVE-2017-12651
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255033
|
9.8 |
CRITICAL
Network
|
loginizer
|
loginizer
|
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
|
CWE-89
SQL Injection
|
CVE-2017-12650
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255034
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12649
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255035
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12648
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255036
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12647
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255037
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12646
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255038
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12645
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255039
|
9.8 |
CRITICAL
Network
|
quest
|
kace_asset_management_appliance kace_systems_management_appliance k1000_as_a_service
|
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
|
CWE-89
SQL Injection
|
CVE-2017-12567
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255040
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadDCMImage in coders\dcm.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12644
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|