|
251241
|
6.5 |
MEDIUM
Network
|
dotcms
|
dotcms
|
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing…
|
CWE-22
Path Traversal
|
CVE-2017-3188
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251242
|
8.8 |
HIGH
Network
|
dotcms
|
dotcms
|
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. A…
|
CWE-352
Origin Validation Error
|
CVE-2017-3187
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251243
|
8.8 |
HIGH
Network
|
sage
|
xrt_treasury
|
Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to privileged database functions. Sage XRT Tr…
|
CWE-863
Incorrect Authorization
|
CVE-2017-3183
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251244
|
6.8 |
MEDIUM
Adjacent
|
threatmetrix
|
threatmetrix_sdk
|
On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an attacker to perform a man-in-the-middle (MITM) atta…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-3182
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251245
|
9.8 |
CRITICAL
Network
|
tibco
|
spotfire_client spotfire_web_player_client spotfire_analyst spotfire_connectors spotfire_deployment_kit spotfire_desktop spotfire_desktop_language_packs
|
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these iss…
|
CWE-89
SQL Injection
|
CVE-2017-3181
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251246
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_automation_services spotfire_desktop spotfire_professional spotfire_web_player spotfire_deployment_kit silver_fabric_enabler_for_spotfire_web_player spotfire_analyst spo…
|
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2017-3180
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251247
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, re…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2860
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251248
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resultin…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2858
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251249
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, re…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2852
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251250
|
8.1 |
HIGH
Network
|
igniterealtime
|
user_import_export
|
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. …
|
CWE-611
XXE
|
CVE-2017-2815
|
2024-11-21 12:24 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|