|
248781
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5832
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248782
|
5.9 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
|
CWE-384
Session Fixation
|
CVE-2017-5831
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248783
|
9.8 |
CRITICAL
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-5830
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248784
|
6.1 |
MEDIUM
Network
|
cpanel
|
cgiecho cgiemail
|
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5616
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248785
|
6.1 |
MEDIUM
Network
|
cpanel
|
cgiecho cgiemail
|
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
|
CWE-601
Open Redirect
|
CVE-2017-5615
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248786
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure …
|
CWE-601
Open Redirect
|
CVE-2017-5614
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248787
|
7.8 |
HIGH
Local
|
cpanel
|
cgiecho cgiemail
|
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2017-5613
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248788
|
7.5 |
HIGH
Network
|
netapp
|
ontap_select_deploy_administration_utility
|
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2017-5995
|
2024-11-21 12:28 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248789
|
5.5 |
MEDIUM
Local
|
zziplib_project
|
zziplib
|
seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
|
CWE-617
Reachable Assertion
|
CVE-2017-5981
|
2024-11-21 12:28 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248790
|
5.5 |
MEDIUM
Local
|
zziplib_project
|
zziplib
|
The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-5980
|
2024-11-21 12:28 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|