|
198081
|
7.5 |
HIGH
Network
|
xinha
|
xinha
|
Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remote attackers to delete any folder via directory traversal sequences in the deld …
|
CWE-22
Path Traversal
|
CVE-2017-11723
|
2024-11-21 12:08 |
2017-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198082
|
9.8 |
CRITICAL
Network
|
lame_project
|
lame
|
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
|
CWE-369
Divide By Zero
|
CVE-2017-11720
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198083
|
6.5 |
MEDIUM
Network
|
graphicsmagick
|
graphicsmagick
|
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11722
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198084
|
9.1 |
CRITICAL
Network
|
medhost
|
medhost_document_management_system
|
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate direct…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-11694
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198085
|
9.1 |
CRITICAL
Network
|
medhost
|
medhost_document_management_system
|
MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-11693
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198086
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other imp…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11719
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198087
|
6.1 |
MEDIUM
Network
|
metinfo_project
|
metinfo
|
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
|
CWE-601
Open Redirect
|
CVE-2017-11718
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198088
|
7.5 |
HIGH
Network
|
metinfo_project
|
metinfo
|
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stre…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2017-11717
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198089
|
6.1 |
MEDIUM
Network
|
metinfo_project
|
metinfo
|
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11716
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198090
|
9.8 |
CRITICAL
Network
|
metinfo_project
|
metinfo
|
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .pht…
|
CWE-94
Code Injection
|
CVE-2017-11715
|
2024-11-21 12:08 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|