|
248861
|
6.1 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5877
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248862
|
6.1 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5876
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248863
|
5.4 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5875
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248864
|
6.1 |
MEDIUM
Network
|
sanadata
|
sanacms
|
Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5882
|
2024-11-21 12:28 |
2017-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248865
|
6.5 |
MEDIUM
Network
|
splunk
|
splunk
|
Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Ligh…
|
CWE-20
Improper Input Validation
|
CVE-2017-5880
|
2024-11-21 12:28 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248866
|
7.5 |
HIGH
Network
|
php
|
pear
|
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via cr…
|
CWE-74
Injection
|
CVE-2017-5630
|
2024-11-21 12:28 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248867
|
6.5 |
MEDIUM
Adjacent
|
asus
|
rt-n56u_firmware
|
An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP address of an affected device, one can crash the de…
|
NVD-CWE-noinfo
|
CVE-2017-5632
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248868
|
7.8 |
HIGH
Local
|
artifex
|
mujs
|
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow wh…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5628
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248869
|
7.8 |
HIGH
Local
|
artifex
|
mujs
|
An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads t…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5627
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248870
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5612
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|