|
248131
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortco…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6814
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248132
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6812
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248133
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6811
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248134
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.fplinks.php (linkid parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6810
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248135
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6809
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248136
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.faq.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6808
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248137
|
7.5 |
HIGH
Network
|
ytnef_project debian
|
ytnef debian_linux
|
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6802
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248138
|
7.5 |
HIGH
Network
|
ytnef_project debian
|
ytnef debian_linux
|
An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6801
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248139
|
7.5 |
HIGH
Network
|
ytnef_project debian
|
ytnef debian_linux
|
An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6800
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248140
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'view_type' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6799
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|