|
248761
|
5.3 |
MEDIUM
Network
|
modx
|
modx_revolution
|
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
|
CWE-22
Path Traversal
|
CVE-2017-8115
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248762
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
|
CWE-200
Information Exposure
|
CVE-2017-8057
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248763
|
6.5 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-7989
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248764
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.6.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of form contents allows overwriting the author of an article.
|
NVD-CWE-noinfo
|
CVE-2017-7988
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248765
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7987
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248766
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7986
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248767
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7985
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248768
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7984
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248769
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
|
CWE-200
Information Exposure
|
CVE-2017-7983
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248770
|
10.0 |
CRITICAL
Network
|
modified-shop
|
modified_ecommerce_shopsoftware
|
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
|
CWE-611
XXE
|
CVE-2017-8110
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|