|
252471
|
5.4 |
MEDIUM
Network
|
tinywebgallery
|
tinywebgallery
|
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accounts for backend acce…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16635
|
2024-11-21 12:16 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252472
|
8.8 |
HIGH
Network
|
keystonejs
|
keystone
|
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests th…
|
CWE-352
Origin Validation Error
|
CVE-2017-16570
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252473
|
4.8 |
MEDIUM
Network
|
zurmo
|
zurmo_crm
|
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
|
CWE-601
Open Redirect
|
CVE-2017-16569
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252474
|
8.8 |
HIGH
Network
|
grandstream
|
ht802_firmware
|
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arb…
|
CWE-352
Origin Validation Error
|
CVE-2017-16565
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252475
|
5.4 |
MEDIUM
Network
|
grandstream
|
ht802_firmware
|
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16564
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252476
|
8.0 |
HIGH
Network
|
grandstream
|
ht802_firmware
|
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
|
CWE-352
Origin Validation Error
|
CVE-2017-16563
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252477
|
8.8 |
HIGH
Network
|
hanwhasecurity
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16524
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252478
|
9.8 |
CRITICAL
Network
|
samba debian canonical
|
rsync debian_linux ubuntu_linux
|
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16548
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252479
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of s…
|
CWE-20
Improper Input Validation
|
CVE-2017-16547
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252480
|
8.8 |
HIGH
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16546
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|