|
252431
|
9.8 |
CRITICAL
Network
|
inedo
|
buildmaster
|
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
|
NVD-CWE-noinfo
|
CVE-2017-16521
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252432
|
5.3 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16754
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252433
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
|
CWE-287
Improper Authentication
|
CVE-2017-16634
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252434
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2017-16633
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252435
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16568
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252436
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a "favorite."
|
CWE-79
Cross-site Scripting
|
CVE-2017-16567
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252437
|
9.8 |
CRITICAL
Network
|
userproplugin
|
userpro
|
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value f…
|
CWE-287
Improper Authentication
|
CVE-2017-16562
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252438
|
7.5 |
HIGH
Network
|
brother
|
dcp-j132w_firmware
|
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with …
|
NVD-CWE-noinfo
|
CVE-2017-16249
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252439
|
5.9 |
MEDIUM
Network
|
librenms
|
librenms
|
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
|
CWE-22
Path Traversal
|
CVE-2017-16759
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252440
|
4.8 |
MEDIUM
Network
|
ultimate_instagram_feed_project
|
ultimate_instagram_feed
|
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16758
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|