|
199361
|
6.1 |
MEDIUM
Network
|
haml debian
|
haml debian_linux
|
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An at…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1002201
|
2024-11-21 12:04 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199362
|
9.8 |
CRITICAL
Network
|
redhat
|
modulemd
|
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
|
CWE-20
Improper Input Validation
|
CVE-2017-1002157
|
2024-11-21 12:04 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199363
|
6.1 |
MEDIUM
Network
|
redhat
|
bodhi
|
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1002152
|
2024-11-21 12:04 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199364
|
8.8 |
HIGH
Network
|
wordpress
|
wordpress
|
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000600
|
2024-11-21 12:04 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199365
|
5.6 |
MEDIUM
Local
|
kubernetes
|
kubernetes
|
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary…
|
NVD-CWE-noinfo
|
CVE-2017-1002102
|
2024-11-21 12:04 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199366
|
9.6 |
CRITICAL
Network
|
kubernetes
|
kubernetes
|
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to …
|
CWE-59
Link Following
|
CVE-2017-1002101
|
2024-11-21 12:04 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199367
|
5.4 |
MEDIUM
Network
|
croogo
|
croogo
|
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000510
|
2024-11-21 12:04 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199368
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000509
|
2024-11-21 12:04 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199369
|
6.1 |
MEDIUM
Network
|
invoiceplane
|
invoiceplane
|
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have be…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000508
|
2024-11-21 12:04 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199370
|
5.4 |
MEDIUM
Network
|
cnvs
|
canvas
|
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000507
|
2024-11-21 12:04 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|