|
252411
|
6.1 |
MEDIUM
Network
|
geminabox_project
|
geminabox
|
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16792
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252412
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cmsmadesimple
|
In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16799
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252413
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16798
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252414
|
7.8 |
HIGH
Local
|
swftools
|
swftools
|
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allows remote attackers to cause a denial of service (…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-16797
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252415
|
7.8 |
HIGH
Local
|
swftools
|
swftools
|
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application cras…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16796
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252416
|
5.5 |
MEDIUM
Local
|
swftools
|
swftools
|
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-b…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16794
|
2024-11-21 12:16 |
2017-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252417
|
7.8 |
HIGH
Local
|
swftools
|
swftools
|
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16793
|
2024-11-21 12:16 |
2017-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252418
|
7.5 |
HIGH
Network
|
inedo
|
buildmaster
|
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
|
CWE-269
Improper Privilege Management
|
CVE-2017-16520
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252419
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16785
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252420
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16784
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|