|
252781
|
8.8 |
HIGH
Network
|
fortunescripts
|
lynda_clone
|
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
|
CWE-352
Origin Validation Error
|
CVE-2017-17903
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252782
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17900
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252783
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17899
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252784
|
7.5 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2017-17898
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252785
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr_erp\/crm
|
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17897
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252786
|
6.1 |
MEDIUM
Network
|
basic_job_site_script_project
|
basic_job_site_script
|
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17896
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252787
|
9.8 |
CRITICAL
Network
|
basic_job_site_script_project
|
basic_job_site_script
|
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.
|
CWE-89
SQL Injection
|
CVE-2017-17895
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252788
|
8.8 |
HIGH
Network
|
basic_job_site_script_project
|
basic_job_site_script
|
Readymade Job Site Script has CSRF via the /job URI.
|
CWE-352
Origin Validation Error
|
CVE-2017-17894
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252789
|
6.1 |
MEDIUM
Network
|
readymade_video_sharing_script_project
|
readymade_video_sharing_script
|
Readymade Video Sharing Script has XSS via the search_video.php search parameter, the viewsubs.php chnlid parameter, or the user-profile-edit.php fname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17893
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252790
|
9.8 |
CRITICAL
Network
|
readymade_video_sharing_script_project
|
readymade_video_sharing_script
|
Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17892
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|