|
198361
|
9.8 |
CRITICAL
Network
|
fiyo
|
fiyo_cms
|
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].
|
CWE-89
SQL Injection
|
CVE-2017-11412
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198362
|
4.9 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/modu…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-11405
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198363
|
4.9 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-11404
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198364
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
|
CWE-416
Use After Free
|
CVE-2017-11403
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198365
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) o…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11399
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198366
|
5.4 |
MEDIUM
Network
|
bolt
|
bolt_cms
|
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11128
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198367
|
5.4 |
MEDIUM
Network
|
bolt
|
bolt_cms
|
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11127
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198368
|
8.8 |
HIGH
Network
|
intenogroup
|
inteno_router_firmware
|
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because …
|
CWE-269
Improper Privilege Management
|
CVE-2017-11361
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198369
|
7.5 |
HIGH
Network
|
shoco_project
|
shoco
|
The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11367
|
2024-11-21 12:07 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198370
|
9.8 |
CRITICAL
Network
|
php
|
php
|
In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buff…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11362
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|