|
258751
|
7.5 |
HIGH
Network
|
sanic_project
|
sanic
|
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
|
CWE-22
Path Traversal
|
CVE-2017-16762
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258752
|
6.1 |
MEDIUM
Network
|
inedo
|
buildmaster
|
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
|
CWE-601
Open Redirect
|
CVE-2017-16761
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258753
|
6.1 |
MEDIUM
Network
|
inedo
|
buildmaster
|
Inedo BuildMaster before 5.8.2 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16760
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258754
|
9.8 |
CRITICAL
Network
|
inedo
|
buildmaster
|
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
|
NVD-CWE-noinfo
|
CVE-2017-16521
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258755
|
5.3 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16754
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258756
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
|
CWE-287
Improper Authentication
|
CVE-2017-16634
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258757
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2017-16633
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258758
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16568
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258759
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a "favorite."
|
CWE-79
Cross-site Scripting
|
CVE-2017-16567
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258760
|
9.8 |
CRITICAL
Network
|
userproplugin
|
userpro
|
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value f…
|
CWE-287
Improper Authentication
|
CVE-2017-16562
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|