|
250911
|
4.8 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 't…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7241
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250912
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denia…
|
CWE-20
Improper Input Validation
|
CVE-2017-7346
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250913
|
8.8 |
HIGH
Network
|
dahuasecurity
|
ip_camera_firmware
|
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with ad…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2017-7253
|
2024-11-21 12:31 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250914
|
9.8 |
CRITICAL
Network
|
modx
|
modx_revolution
|
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
|
CWE-94
Code Injection
|
CVE-2017-7324
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250915
|
8.1 |
HIGH
Network
|
modx
|
modx_revolution
|
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger…
|
NVD-CWE-noinfo
|
CVE-2017-7323
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250916
|
8.1 |
HIGH
Network
|
modx
|
modx_revolution
|
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serve…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-7322
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250917
|
9.8 |
CRITICAL
Network
|
modx
|
modx_revolution
|
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.
|
CWE-94
Code Injection
|
CVE-2017-7321
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250918
|
6.1 |
MEDIUM
Network
|
modx
|
modx_revolution
|
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a …
|
CWE-79
Cross-site Scripting
|
CVE-2017-7320
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250919
|
9.8 |
CRITICAL
Network
|
siklu
|
etherhaul_firmware
|
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as…
|
NVD-CWE-noinfo
|
CVE-2017-7318
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250920
|
7.2 |
HIGH
Network
|
xoops
|
xoops
|
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An …
|
CWE-89
SQL Injection
|
CVE-2017-7290
|
2024-11-21 12:31 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|