|
258321
|
8.8 |
HIGH
Network
|
project_hashtopussy
|
hashtopussy
|
Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for administrative roles, as demonstrated by an action=c…
|
CWE-269
Improper Privilege Management
|
CVE-2017-11681
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258322
|
8.8 |
HIGH
Network
|
project_hashtopussy
|
hashtopussy
|
Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.
|
CWE-352
Origin Validation Error
|
CVE-2017-11680
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258323
|
8.8 |
HIGH
Network
|
hashtopus_project
|
hashtopus
|
Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.
|
CWE-352
Origin Validation Error
|
CVE-2017-11679
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258324
|
8.8 |
HIGH
Network
|
hashtopus_project
|
hashtopus
|
SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via the format parameter in admin.php.
|
CWE-89
SQL Injection
|
CVE-2017-11678
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258325
|
6.1 |
MEDIUM
Network
|
hashtopus_project
|
hashtopus
|
Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTML via the query string to admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11677
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258326
|
8.8 |
HIGH
Network
|
zen-cart
|
zen_cart
|
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP …
|
CWE-94
Code Injection
|
CVE-2017-11675
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258327
|
5.5 |
MEDIUM
Local
|
acunetix
|
web_vulnerability_scanner
|
Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11674
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258328
|
9.8 |
CRITICAL
Network
|
acunetix
|
web_vulnerability_scanner
|
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Write AV starting at re…
|
CWE-20
Improper Input Validation
|
CVE-2017-11673
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258329
|
4.0 |
MEDIUM
Local
|
gnu
|
gcc
|
Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2017-11671
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258330
|
8.1 |
HIGH
Network
|
openproject
|
openproject
|
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
|
CWE-613
Insufficient Session Expiration
|
CVE-2017-11667
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|