|
247261
|
8.8 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modu…
|
CWE-89
SQL Injection
|
CVE-2017-9443
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247262
|
6.1 |
MEDIUM
Network
|
sunnythemes
|
spiffy_calendar
|
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9420
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247263
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-9440
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247264
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-9439
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247265
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_em…
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-9438
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247266
|
8.8 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename pa…
|
CWE-94
Code Injection
|
CVE-2017-9442
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247267
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9441
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247268
|
8.8 |
HIGH
Network
|
openbravo
|
openbravo_erp
|
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
|
CWE-89
SQL Injection
|
CVE-2017-9437
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247269
|
9.8 |
CRITICAL
Network
|
teampass
|
teampass
|
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
|
CWE-89
SQL Injection
|
CVE-2017-9436
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247270
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).
|
CWE-89
SQL Injection
|
CVE-2017-9435
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|