|
247391
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Paramet…
|
CWE-89
SQL Injection
|
CVE-2017-6570
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247392
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6562
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247393
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6561
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247394
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6560
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247395
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6559
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247396
|
9.8 |
CRITICAL
Network
|
iball
|
ib-wra150n_firmware
|
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-6558
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247397
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings …
|
CWE-79
Cross-site Scripting
|
CVE-2017-6556
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247398
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6555
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247399
|
7.5 |
HIGH
Network
|
sagemcom
|
livebox_firmware
|
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-6552
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247400
|
8.8 |
HIGH
Network
|
asus
|
rt-ac53_firmware
|
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B…
|
CWE-287
Improper Authentication
|
CVE-2017-6549
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|