|
198041
|
6.1 |
MEDIUM
Network
|
event_list_project
|
event_list
|
The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12068
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198042
|
7.5 |
HIGH
Network
|
potrace_project
|
potrace
|
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12067
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198043
|
5.4 |
MEDIUM
Network
|
cacti
|
cacti
|
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer hea…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12066
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198044
|
9.8 |
CRITICAL
Network
|
cacti
|
cacti
|
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
|
NVD-CWE-noinfo
|
CVE-2017-12065
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198045
|
7.5 |
HIGH
Network
|
open-emr
|
openemr
|
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2017-12064
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198046
|
6.1 |
MEDIUM
Network
|
connectwise
|
manage
|
services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafte…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11727
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198047
|
8.8 |
HIGH
Network
|
connectwise
|
manage
|
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by changing an e-mail address setting.
|
CWE-352
Origin Validation Error
|
CVE-2017-11726
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198048
|
8.8 |
HIGH
Network
|
techroutes
|
tr_1803-3g_firmware
|
Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a goform/BasicSettings request to disable port filte…
|
CWE-352
Origin Validation Error
|
CVE-2017-11648
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198049
|
8.8 |
HIGH
Network
|
projeqtor
|
projeqtor
|
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated…
|
CWE-94
Code Injection
|
CVE-2017-11760
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198050
|
7.5 |
HIGH
Network
|
eapmd5pass_project
|
eapmd5pass
|
A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-11670
|
2024-11-21 12:08 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|