|
252771
|
9.8 |
CRITICAL
Network
|
sistemagpweb
|
gpweb
|
SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15875
|
2024-11-21 12:15 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252772
|
8.8 |
HIGH
Network
|
apache
|
sling_authentication_service
|
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over …
|
CWE-200
Information Exposure
|
CVE-2017-15700
|
2024-11-21 12:15 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252773
|
4.8 |
MEDIUM
Network
|
synology
|
mailplus_server
|
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15890
|
2024-11-21 12:15 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252774
|
3.1 |
LOW
Network
|
nodejs
|
node.js
|
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This…
|
CWE-665
Improper Initialization
|
CVE-2017-15897
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252775
|
9.1 |
CRITICAL
Network
|
nodejs
|
node.js
|
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application dat…
|
NVD-CWE-noinfo
|
CVE-2017-15896
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252776
|
5.3 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-15943
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252777
|
7.5 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management in…
|
NVD-CWE-noinfo
|
CVE-2017-15942
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252778
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to…
|
CWE-77
Command Injection
|
CVE-2017-15940
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252779
|
6.7 |
MEDIUM
Local
|
paloaltonetworks
|
globalprotect
|
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."
|
NVD-CWE-noinfo
|
CVE-2017-15870
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252780
|
9.8 |
CRITICAL
Network
|
apache oracle
|
synapse peoplesoft_enterprise_peopletools financial_services_market_risk_measurement_and_management
|
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows r…
|
CWE-74
Injection
|
CVE-2017-15708
|
2024-11-21 12:15 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|