|
250011
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6817
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250012
|
4.9 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
|
CWE-863
Incorrect Authorization
|
CVE-2017-6816
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250013
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
|
CWE-20
Improper Input Validation
|
CVE-2017-6815
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250014
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortco…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6814
|
2024-11-21 12:30 |
2017-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250015
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6812
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250016
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6811
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250017
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.fplinks.php (linkid parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6810
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250018
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6809
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250019
|
6.1 |
MEDIUM
Network
|
mangoswebv4_project
|
mangoswebv4
|
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.faq.php (id parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-6808
|
2024-11-21 12:30 |
2017-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250020
|
7.5 |
HIGH
Network
|
ytnef_project debian
|
ytnef debian_linux
|
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6802
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|