|
198621
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted re…
|
CWE-352
Origin Validation Error
|
CVE-2017-10680
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198622
|
7.5 |
HIGH
Network
|
piwigo
|
piwigo
|
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID…
|
CWE-200
Information Exposure
|
CVE-2017-10679
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198623
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
|
CWE-352
Origin Validation Error
|
CVE-2017-10678
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198624
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10673
|
2024-11-21 12:06 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198625
|
9.8 |
CRITICAL
Network
|
xml-libxml_project debian
|
xml-libxml debian_linux
|
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
|
CWE-416
Use After Free
|
CVE-2017-10672
|
2024-11-21 12:06 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198626
|
7.8 |
HIGH
Local
|
sthttpd_project
|
sthttpd
|
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impa…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-10671
|
2024-11-21 12:06 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198627
|
6.1 |
MEDIUM
Network
|
zen-cart
|
zen_cart
|
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10667
|
2024-11-21 12:06 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198628
|
7.8 |
HIGH
Local
|
postfix
|
postfix
|
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and late…
|
NVD-CWE-noinfo
|
CVE-2017-10140
|
2024-11-21 12:05 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198629
|
8.1 |
HIGH
Network
|
oracle
|
peoplesoft_enterprise_peopletools
|
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exp…
|
NVD-CWE-noinfo
|
CVE-2017-10301
|
2024-11-21 12:05 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198630
|
9.1 |
CRITICAL
Network
|
oracle
|
database_server
|
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker h…
|
NVD-CWE-noinfo
|
CVE-2017-10282
|
2024-11-21 12:05 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|