|
253721
|
5.9 |
MEDIUM
Network
|
meafinancial
|
freedom_1st_credit_union_mobile_banking
|
The Freedom First freedom-1st-credit-union-mobile-banking/id1085229458 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9562
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253722
|
5.9 |
MEDIUM
Network
|
lbtc
|
lee_bank_\&_trust
|
The Lee Bank & Trust lbtc-mobile/id1068984753 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inf…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9561
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253723
|
5.9 |
MEDIUM
Network
|
cayugalakenationalbank
|
cayuga_lake_national_bank
|
The cayuga-lake-national-bank/id1151601539 app 4.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9560
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253724
|
5.9 |
MEDIUM
Network
|
meafinancial
|
vision_bank
|
The MEA Financial vision-bank/id420406345 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informa…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9559
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253725
|
5.9 |
MEDIUM
Network
|
wawacu
|
wawa_employees_credit_union_mobile
|
The wawa-employees-credit-union-mobile/id1158082793 app 4.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensiti…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9558
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253726
|
7.5 |
HIGH
Network
|
dlink
|
dir-605l_firmware
|
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
|
CWE-20
Improper Input Validation
|
CVE-2017-9675
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253727
|
6.1 |
MEDIUM
Network
|
webhammer
|
wp_custom_fields_search
|
Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9419
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253728
|
5.4 |
MEDIUM
Network
|
simplece
|
simplece
|
In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on index.php/content/text/1?return_url=[XSS] exploitable as a regular or admin user.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9674
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253729
|
8.8 |
HIGH
Network
|
simplece
|
simplece
|
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.
|
CWE-352
Origin Validation Error
|
CVE-2017-9673
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253730
|
5.4 |
MEDIUM
Network
|
sap
|
successfactors
|
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9613
|
2024-11-21 12:36 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|