|
248121
|
6.1 |
MEDIUM
Network
|
lutim_project
|
lutim
|
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6877
|
2024-11-21 12:30 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248122
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via cr…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2017-6874
|
2024-11-21 12:30 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248123
|
6.1 |
MEDIUM
Network
|
uninett
|
mod_auth_mellon
|
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6807
|
2024-11-21 12:30 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248124
|
8.8 |
HIGH
Network
|
fiyo
|
fiyo_cms
|
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2017-6823
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248125
|
6.1 |
MEDIUM
Network
|
roundcube
|
webmail
|
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6820
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248126
|
6.5 |
MEDIUM
Network
|
wordpress
|
wordpress
|
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an …
|
CWE-352
Origin Validation Error
|
CVE-2017-6819
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248127
|
6.1 |
MEDIUM
Network
|
wordpress
|
wordpress
|
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6818
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248128
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6817
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248129
|
4.9 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
|
CWE-863
Incorrect Authorization
|
CVE-2017-6816
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248130
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
|
CWE-20
Improper Input Validation
|
CVE-2017-6815
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|