|
254791
|
8.8 |
HIGH
Network
|
userscape
|
helpspot
|
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker …
|
CWE-352
Origin Validation Error
|
CVE-2017-16756
|
2024-11-21 12:16 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254792
|
6.1 |
MEDIUM
Network
|
userscape
|
helpspot
|
An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16755
|
2024-11-21 12:16 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254793
|
9.8 |
CRITICAL
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The speci…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-16610
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254794
|
7.5 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. T…
|
CWE-200
Information Exposure
|
CVE-2017-16609
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254795
|
9.8 |
CRITICAL
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The speci…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2017-16608
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254796
|
7.5 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. T…
|
CWE-200
Information Exposure
|
CVE-2017-16607
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254797
|
8.8 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-16606
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254798
|
6.5 |
MEDIUM
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to ex…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-16605
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254799
|
6.5 |
MEDIUM
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to ex…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-16604
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254800
|
8.8 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-16603
|
2024-11-21 12:16 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|