|
256171
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15201
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256172
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15200
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256173
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15199
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256174
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
|
CWE-200
Information Exposure
|
CVE-2017-15198
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256175
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15197
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256176
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15196
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256177
|
4.3 |
MEDIUM
Network
|
kanboard
|
kanboard
|
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2017-15195
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256178
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15194
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256179
|
4.8 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array par…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15188
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256180
|
9.8 |
CRITICAL
Network
|
zyxel
|
nbg6716_firmware
|
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.
|
CWE-78
OS Command
|
CVE-2017-15226
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|