|
248951
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_tm221ce16r_firmware
|
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x00\x05\x01\x5a\x00\x03\x00 request to the Modbus p…
|
CWE-200
Information Exposure
|
CVE-2017-7575
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248952
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_tm221ce16r_firmware somachine
|
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-7574
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248953
|
8.0 |
HIGH
Network
|
ladybirdweb
|
faveo_helpdesk
|
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
|
CWE-352
Origin Validation Error
|
CVE-2017-7571
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248954
|
8.6 |
HIGH
Network
|
vbulletin
|
vbulletin
|
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-7569
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248955
|
7.7 |
HIGH
Network
|
mybb
|
mybb
|
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-7566
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248956
|
8.8 |
HIGH
Network
|
splunk
|
hadoop_connect
|
Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.
|
CWE-22
Path Traversal
|
CVE-2017-7565
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248957
|
8.1 |
HIGH
Network
|
backintime_project
|
backintime
|
The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condi…
|
CWE-362
Race Condition
|
CVE-2017-7572
|
2024-11-21 12:32 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248958
|
7.5 |
HIGH
Network
|
botan_project
|
botan
|
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-7252
|
2024-11-21 12:31 |
2023-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248959
|
8.8 |
HIGH
Network
|
cloudera
|
cloudera_manager
|
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those…
|
CWE-269
Improper Privilege Management
|
CVE-2017-7399
|
2024-11-21 12:31 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248960
|
7.5 |
HIGH
Network
|
php
|
php
|
main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later tr…
|
CWE-20
Improper Input Validation
|
CVE-2017-7189
|
2024-11-21 12:31 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|