|
266231
|
7.3 |
HIGH
Network
|
modx
|
modx_revolution
|
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, re…
|
CWE-22
Path Traversal
|
CVE-2016-10037
|
2024-11-21 11:43 |
2016-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266232
|
7.5 |
HIGH
Network
|
sap
|
solution_manager
|
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
|
CWE-200
Information Exposure
|
CVE-2016-10005
|
2024-11-21 11:43 |
2016-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266233
|
7.5 |
HIGH
Network
|
ruckus
|
wireless_h500
|
Ruckus Wireless H500 web management interface denial of service
|
NVD-CWE-noinfo
|
CVE-2016-1000215
|
2024-11-21 11:43 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266234
|
5.3 |
MEDIUM
Network
|
ruckus
|
wireless_h500
|
Ruckus Wireless H500 web management interface authentication bypass
|
CWE-287 CWE-200
Improper Authentication Information Exposure
|
CVE-2016-1000214
|
2024-11-21 11:43 |
2016-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266235
|
8.8 |
HIGH
Network
|
ruckus
|
wireless_h500
|
Ruckus Wireless H500 web management interface authenticated command injection
|
CWE-78
OS Command
|
CVE-2016-1000216
|
2024-11-21 11:43 |
2016-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266236
|
9.8 |
CRITICAL
Network
|
zotpress_project
|
zotpress
|
Zotpress plugin for WordPress SQLi in zp_get_account()
|
CWE-89
SQL Injection
|
CVE-2016-1000217
|
2024-11-21 11:43 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266237
|
7.5 |
HIGH
Network
|
mb.miniaudioplayer_project
|
mb.miniaudioplayer
|
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properl…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2016-0796
|
2024-11-21 11:42 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266238
|
5.3 |
MEDIUM
Network
|
twistedmatrix
|
twisted
|
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PR…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2016-1000111
|
2024-11-21 11:42 |
2020-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266239
|
5.3 |
MEDIUM
Network
|
facebook
|
hhvm
|
HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment v…
|
CWE-665
Improper Initialization
|
CVE-2016-1000109
|
2024-11-21 11:42 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266240
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9…
|
CWE-843
Type Confusion
|
CVE-2016-1000005
|
2024-11-21 11:42 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|