|
248061
|
6.5 |
MEDIUM
Network
|
asus
|
rt-ac1750_firmware
|
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.
|
CWE-200
Information Exposure
|
CVE-2017-8877
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248062
|
6.1 |
MEDIUM
Network
|
getsymphony
|
symphony
|
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8876
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248063
|
6.5 |
MEDIUM
Network
|
codection
|
clean_login
|
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
|
CWE-352
Origin Validation Error
|
CVE-2017-8875
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248064
|
8.8 |
HIGH
Network
|
acquia
|
mautic
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete cont…
|
CWE-352
Origin Validation Error
|
CVE-2017-8874
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248065
|
9.1 |
CRITICAL
Network
|
xmlsoft
|
libxml2
|
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8872
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248066
|
7.5 |
HIGH
Network
|
flatcore
|
flatcore-cms
|
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.
|
CWE-22
Path Traversal
|
CVE-2017-8868
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248067
|
9.8 |
CRITICAL
Network
|
veritas
|
netbackup_appliance
|
In Veritas NetBackup Appliance 3.0 and earlier, unauthenticated users can execute arbitrary commands as root.
|
NVD-CWE-noinfo
|
CVE-2017-8859
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248068
|
9.8 |
CRITICAL
Network
|
veritas
|
netbackup_appliance netbackup
|
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' process.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-8858
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248069
|
9.8 |
CRITICAL
Network
|
veritas
|
netbackup_appliance netbackup
|
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-8857
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248070
|
9.8 |
CRITICAL
Network
|
veritas
|
netbackup_appliance netbackup
|
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-8856
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|