|
254391
|
7.5 |
HIGH
Network
|
iwcnetwork
|
shift
|
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
|
CWE-275
Permission Issues
|
CVE-2017-17876
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254392
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_faq_pro
|
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17875
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254393
|
8.8 |
HIGH
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-17874
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254394
|
9.8 |
CRITICAL
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
|
CWE-89
SQL Injection
|
CVE-2017-17873
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254395
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_video_gallery
|
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17872
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254396
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_question_and_answer
|
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17871
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254397
|
9.8 |
CRITICAL
Network
|
jbuildozer
|
jbuildozer
|
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
|
CWE-89
SQL Injection
|
CVE-2017-17870
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254398
|
6.1 |
MEDIUM
Network
|
mgl-instagram-gallery_project
|
mgl-instagram-gallery
|
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17869
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254399
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17868
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254400
|
7.8 |
HIGH
Local
|
artifex debian
|
mupdf debian_linux
|
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (b…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17866
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|