|
198111
|
6.1 |
MEDIUM
Network
|
hashtopus_project
|
hashtopus
|
Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTML via the query string to admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11677
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198112
|
8.8 |
HIGH
Network
|
zen-cart
|
zen_cart
|
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP …
|
CWE-94
Code Injection
|
CVE-2017-11675
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198113
|
5.5 |
MEDIUM
Local
|
acunetix
|
web_vulnerability_scanner
|
Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11674
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198114
|
9.8 |
CRITICAL
Network
|
acunetix
|
web_vulnerability_scanner
|
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Write AV starting at re…
|
CWE-20
Improper Input Validation
|
CVE-2017-11673
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198115
|
4.0 |
MEDIUM
Local
|
gnu
|
gcc
|
Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2017-11671
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198116
|
8.1 |
HIGH
Network
|
openproject
|
openproject
|
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
|
CWE-613
Insufficient Session Expiration
|
CVE-2017-11667
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198117
|
6.1 |
MEDIUM
Network
|
kopano
|
webapp
|
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11666
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198118
|
7.5 |
HIGH
Network
|
wp-rocket
|
wp-rocket
|
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypa…
|
CWE-22
Path Traversal
|
CVE-2017-11658
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198119
|
8.6 |
HIGH
Local
|
factorio
|
factorio
|
A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.
|
NVD-CWE-noinfo
|
CVE-2017-11615
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198120
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11612
|
2024-11-21 12:08 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|