|
254201
|
8.7 |
HIGH
Network
|
atlassian
|
application_links
|
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulner…
|
CWE-611
XXE
|
CVE-2017-18111
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254202
|
6.5 |
MEDIUM
Network
|
atlassian
|
crowd
|
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vuln…
|
CWE-611
XXE
|
CVE-2017-18110
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254203
|
6.1 |
MEDIUM
Network
|
atlassian
|
crowd
|
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use a…
|
CWE-601
Open Redirect
|
CVE-2017-18109
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254204
|
7.2 |
HIGH
Network
|
atlassian
|
crowd
|
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.
|
CWE-94
Code Injection
|
CVE-2017-18108
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254205
|
7.5 |
HIGH
Network
|
atlassian
|
crowd
|
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remo…
|
CWE-287
Improper Authentication
|
CVE-2017-18106
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254206
|
8.1 |
HIGH
Network
|
atlassian
|
crowd
|
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gai…
|
CWE-384
Session Fixation
|
CVE-2017-18105
|
2024-11-21 12:19 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254207
|
9.8 |
CRITICAL
Network
|
github
|
github
|
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise s…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-18365
|
2024-11-21 12:19 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254208
|
6.1 |
MEDIUM
Network
|
frank-karau
|
phpfk
|
phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18364
|
2024-11-21 12:19 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254209
|
9.8 |
CRITICAL
Network
|
connectwise
|
manageditsync
|
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attacker…
|
CWE-89
SQL Injection
|
CVE-2017-18362
|
2024-11-21 12:19 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254210
|
7.5 |
HIGH
Network
|
pylonsproject
|
colander
|
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18361
|
2024-11-21 12:19 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|