|
247091
|
5.3 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request t…
|
CWE-200
Information Exposure
|
CVE-2017-8840
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247092
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/p…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8839
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247093
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/H…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8838
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247094
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in questio…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-8837
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247095
|
8.8 |
HIGH
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative inte…
|
CWE-352
Origin Validation Error
|
CVE-2017-8836
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247096
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth coo…
|
CWE-89
SQL Injection
|
CVE-2017-8835
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247097
|
4.3 |
MEDIUM
Network
|
elastic
|
x-pack
|
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data…
|
CWE-200
Information Exposure
|
CVE-2017-8441
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247098
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions …
|
CWE-79
Cross-site Scripting
|
CVE-2017-8440
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247099
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8439
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247100
|
8.8 |
HIGH
Network
|
elastic
|
x-pack
|
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. …
|
CWE-269
Improper Privilege Management
|
CVE-2017-8438
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|