|
257181
|
9.8 |
CRITICAL
Network
|
python debian
|
python debian_linux
|
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code ex…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-1000158
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257182
|
7.5 |
HIGH
Network
|
s9y
|
serendipity
|
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
|
CWE-89
SQL Injection
|
CVE-2017-1000129
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257183
|
7.5 |
HIGH
Network
|
codiad
|
codiad
|
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-1000125
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257184
|
9.8 |
CRITICAL
Network
|
redis-store
|
redis-store
|
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-1000248
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257185
|
7.5 |
HIGH
Network
|
codeigniter
|
codeigniter
|
British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.
|
CWE-20
Improper Input Validation
|
CVE-2017-1000247
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257186
|
5.3 |
MEDIUM
Network
|
pysaml2_project
|
pysaml2
|
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-1000246
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257187
|
9.8 |
CRITICAL
Network
|
i-librarian
|
i_librarian
|
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-1000237
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257188
|
6.1 |
MEDIUM
Network
|
i-librarian
|
i_librarian
|
I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000236
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257189
|
9.8 |
CRITICAL
Network
|
i-librarian
|
i_librarian
|
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
|
CWE-78
OS Command
|
CVE-2017-1000235
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257190
|
5.3 |
MEDIUM
Network
|
i-librarian
|
i_librarian
|
I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simply by navigating through the "dir" parameter
|
CWE-200
Information Exposure
|
CVE-2017-1000234
|
2024-11-21 12:04 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|