|
256361
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execu…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12062
|
2024-11-21 12:08 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256362
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under user control in the MantisBT installation script are not properly sanitized befor…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12061
|
2024-11-21 12:08 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256363
|
6.5 |
MEDIUM
Network
|
underbit
|
mad_libmad
|
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decode…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11552
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256364
|
6.1 |
MEDIUM
Network
|
goldplugins
|
easy_testimonials
|
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excer…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12131
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256365
|
6.1 |
MEDIUM
Network
|
event_list_project
|
event_list
|
The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12068
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256366
|
7.5 |
HIGH
Network
|
potrace_project
|
potrace
|
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12067
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256367
|
5.4 |
MEDIUM
Network
|
cacti
|
cacti
|
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer hea…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12066
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256368
|
9.8 |
CRITICAL
Network
|
cacti
|
cacti
|
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
|
NVD-CWE-noinfo
|
CVE-2017-12065
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256369
|
7.5 |
HIGH
Network
|
open-emr
|
openemr
|
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2017-12064
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256370
|
6.1 |
MEDIUM
Network
|
connectwise
|
manage
|
services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafte…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11727
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|