|
253841
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16784
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253842
|
9.8 |
CRITICAL
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
|
CWE-94
Code Injection
|
CVE-2017-16783
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253843
|
6.1 |
MEDIUM
Network
|
home-assistant
|
home-assistant
|
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16782
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253844
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
The installer in MyBB before 1.8.13 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16781
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253845
|
9.8 |
CRITICAL
Network
|
mybb
|
mybb
|
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
|
CWE-352
Origin Validation Error
|
CVE-2017-16780
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253846
|
6.1 |
MEDIUM
Network
|
dlink
|
dwr-933_firmware
|
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16765
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253847
|
9.8 |
CRITICAL
Network
|
django_make_app_project
|
django_make_app
|
An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulti…
|
NVD-CWE-noinfo
|
CVE-2017-16764
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253848
|
9.8 |
CRITICAL
Network
|
confire_project
|
confire
|
An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being loaded from "~/.confire.yaml" using the yaml.load fun…
|
NVD-CWE-noinfo
|
CVE-2017-16763
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253849
|
7.5 |
HIGH
Network
|
sanic_project
|
sanic
|
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
|
CWE-22
Path Traversal
|
CVE-2017-16762
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253850
|
6.1 |
MEDIUM
Network
|
inedo
|
buildmaster
|
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
|
CWE-601
Open Redirect
|
CVE-2017-16761
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|