|
197591
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
|
CWE-89
SQL Injection
|
CVE-2017-14403
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197592
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input v…
|
CWE-89
SQL Injection
|
CVE-2017-14402
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197593
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
|
CWE-89
SQL Injection
|
CVE-2017-14401
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197594
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14400
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197595
|
8.8 |
HIGH
Network
|
blackcat-cms
|
blackcat_cms
|
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14399
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197596
|
9.8 |
CRITICAL
Network
|
anydesk
|
anydesk
|
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
|
CWE-74
Injection
|
CVE-2017-14397
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197597
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
|
CWE-89
SQL Injection
|
CVE-2017-14396
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197598
|
8.8 |
HIGH
Network
|
libraw
|
libraw
|
LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14348
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197599
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14347
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197600
|
9.8 |
CRITICAL
Network
|
blog_project
|
blog
|
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14346
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|