|
248231
|
9.9 |
CRITICAL
Network
|
nfsen
|
nfsen
|
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).
|
CWE-78
OS Command
|
CVE-2017-7175
|
2024-11-21 12:31 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248232
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor ne…
|
CWE-295 CWE-311
Improper Certificate Validation Missing Encryption of Sensitive Data
|
CVE-2017-7406
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248233
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an att…
|
CWE-287
Improper Authentication
|
CVE-2017-7405
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248234
|
8.8 |
HIGH
Network
|
dlink
|
dir-615
|
On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim…
|
CWE-352
Origin Validation Error
|
CVE-2017-7404
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248235
|
6.1 |
MEDIUM
Network
|
topdesk
|
topdesk
|
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7276
|
2024-11-21 12:31 |
2017-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248236
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hg100r_firmware
|
An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin.
|
CWE-200
Information Exposure
|
CVE-2017-7317
|
2024-11-21 12:31 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248237
|
6.1 |
MEDIUM
Network
|
humaxdigital
|
hg100r_firmware
|
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7316
|
2024-11-21 12:31 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248238
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hg100r_firmware
|
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup,…
|
CWE-306 CWE-522
Missing Authentication for Critical Function Insufficiently Protected Credentials
|
CVE-2017-7315
|
2024-11-21 12:31 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248239
|
7.5 |
HIGH
Network
|
ntop
|
ntopng
|
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7458
|
2024-11-21 12:31 |
2017-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248240
|
7.5 |
HIGH
Network
|
ntop
|
ntopng
|
ntopng before 3.0 allows HTTP Response Splitting.
|
CWE-74
Injection
|
CVE-2017-7459
|
2024-11-21 12:31 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|