|
248151
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter…
|
CWE-89
SQL Injection
|
CVE-2017-6574
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248152
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.
|
CWE-89
SQL Injection
|
CVE-2017-6573
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248153
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_…
|
CWE-89
SQL Injection
|
CVE-2017-6572
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248154
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: i…
|
CWE-89
SQL Injection
|
CVE-2017-6571
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248155
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Paramet…
|
CWE-89
SQL Injection
|
CVE-2017-6570
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248156
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6562
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248157
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6561
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248158
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6560
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248159
|
6.1 |
MEDIUM
Network
|
agora-project
|
agora-project
|
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6559
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248160
|
9.8 |
CRITICAL
Network
|
iball
|
ib-wra150n_firmware
|
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-6558
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|