|
247081
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single …
|
NVD-CWE-noinfo
|
CVE-2017-9855
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247082
|
9.8 |
CRITICAL
Network
|
greenpacket
|
dx-350_firmware
|
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.
|
CWE-77
Command Injection
|
CVE-2017-9980
|
2024-11-21 12:37 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247083
|
9.8 |
CRITICAL
Network
|
greenpacket
|
dx-350_firmware
|
Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb has a default password of admin for the admin account.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9932
|
2024-11-21 12:37 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247084
|
6.1 |
MEDIUM
Network
|
greenpacket
|
dx-350_firmware
|
Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9931
|
2024-11-21 12:37 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247085
|
8.8 |
HIGH
Network
|
greenpacket
|
dx-350_firmware
|
Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi that enables UPnP.
|
CWE-352
Origin Validation Error
|
CVE-2017-9930
|
2024-11-21 12:37 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247086
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9934
|
2024-11-21 12:37 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247087
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
|
CWE-200
Information Exposure
|
CVE-2017-9933
|
2024-11-21 12:37 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247088
|
7.5 |
HIGH
Network
|
memcached
|
memcached
|
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a compari…
|
NVD-CWE-noinfo
|
CVE-2017-9951
|
2024-11-21 12:37 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247089
|
7.5 |
HIGH
Network
|
avg
|
anti-virus
|
AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.
|
NVD-CWE-noinfo
|
CVE-2017-9977
|
2024-11-21 12:37 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247090
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to a "Read Access Violation …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9927
|
2024-11-21 12:37 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|