|
252761
|
8.1 |
HIGH
Network
|
rubyonrails
|
rails
|
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes th…
|
CWE-89
SQL Injection
|
CVE-2017-17916
|
2024-11-21 12:18 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252762
|
9.8 |
CRITICAL
Network
|
resume_clone_script_project
|
resume_clone_script
|
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17931
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252763
|
8.8 |
HIGH
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.
|
CWE-352
Origin Validation Error
|
CVE-2017-17930
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252764
|
4.8 |
MEDIUM
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17929
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252765
|
9.8 |
CRITICAL
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17928
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252766
|
5.3 |
MEDIUM
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/.
|
CWE-22
Path Traversal
|
CVE-2017-17927
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252767
|
5.3 |
MEDIUM
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
|
CWE-200
Information Exposure
|
CVE-2017-17926
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252768
|
4.8 |
MEDIUM
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17925
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252769
|
5.3 |
MEDIUM
Network
|
ordermanagementscript
|
professional_service_script
|
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.
|
CWE-22
Path Traversal
|
CVE-2017-17924
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252770
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17915
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|