|
247171
|
5.4 |
MEDIUM
Network
|
modx
|
modx_revolution
|
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9070
|
2024-11-21 12:35 |
2017-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247172
|
8.8 |
HIGH
Network
|
modx
|
modx_revolution
|
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-9069
|
2024-11-21 12:35 |
2017-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247173
|
6.1 |
MEDIUM
Network
|
modx
|
modx_revolution
|
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9068
|
2024-11-21 12:35 |
2017-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247174
|
7.0 |
HIGH
Local
|
modx php
|
modx_revolution php
|
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/i…
|
CWE-22
Path Traversal
|
CVE-2017-9067
|
2024-11-21 12:35 |
2017-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247175
|
8.6 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-9066
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247176
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
|
CWE-20
Improper Input Validation
|
CVE-2017-9065
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247177
|
8.8 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
|
CWE-352
Origin Validation Error
|
CVE-2017-9064
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247178
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9063
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247179
|
8.6 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
|
CWE-352 CWE-79 CWE-601
Origin Validation Error Cross-site Scripting Open Redirect
|
CVE-2017-9062
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247180
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filen…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9061
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|