|
198591
|
6.1 |
MEDIUM
Network
|
simplerisk
|
simplerisk
|
In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10711
|
2024-11-21 12:06 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198592
|
8.8 |
HIGH
Network
|
contao
|
contao_cms
|
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2017-10993
|
2024-11-21 12:06 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198593
|
6.1 |
MEDIUM
Network
|
d-link
|
dir-600m_firmware
|
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10676
|
2024-11-21 12:06 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198594
|
6.1 |
MEDIUM
Network
|
phpsocial
|
phpsocial
|
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10801
|
2024-11-21 12:06 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198595
|
7.8 |
HIGH
Local
|
apport_project
|
apport
|
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path tra…
|
CWE-22
Path Traversal
|
CVE-2017-10708
|
2024-11-21 12:06 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198596
|
6.1 |
MEDIUM
Network
|
vanderbilt
|
redcap
|
REDCap before 7.5.1 has XSS via the query string.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10962
|
2024-11-21 12:06 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198597
|
8.8 |
HIGH
Network
|
vanderbilt
|
redcap
|
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
|
CWE-352
Origin Validation Error
|
CVE-2017-10961
|
2024-11-21 12:06 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198598
|
7.5 |
HIGH
Network
|
freeradius
|
freeradius
|
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-10987
|
2024-11-21 12:06 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198599
|
7.5 |
HIGH
Network
|
freeradius
|
freeradius
|
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-10986
|
2024-11-21 12:06 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198600
|
7.5 |
HIGH
Network
|
freeradius
|
freeradius
|
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-10985
|
2024-11-21 12:06 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|