|
251381
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
steam_link_firmware
|
An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" settin…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-17878
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251382
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
steam_link_firmware
|
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless ad…
|
NVD-CWE-noinfo
|
CVE-2017-17877
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251383
|
7.5 |
HIGH
Network
|
iwcnetwork
|
shift
|
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
|
CWE-275
Permission Issues
|
CVE-2017-17876
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251384
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_faq_pro
|
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17875
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251385
|
8.8 |
HIGH
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-17874
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251386
|
9.8 |
CRITICAL
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
|
CWE-89
SQL Injection
|
CVE-2017-17873
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251387
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_video_gallery
|
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17872
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251388
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_question_and_answer
|
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17871
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251389
|
9.8 |
CRITICAL
Network
|
jbuildozer
|
jbuildozer
|
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
|
CWE-89
SQL Injection
|
CVE-2017-17870
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251390
|
6.1 |
MEDIUM
Network
|
mgl-instagram-gallery_project
|
mgl-instagram-gallery
|
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17869
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|