Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-427h-jcwm-rr2p

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.

EPSS: Низкий
github логотип

GHSA-427h-gjgj-xjwc

больше 3 лет назад

SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

EPSS: Низкий
github логотип

GHSA-427h-c47c-jgj4

больше 3 лет назад

OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.

EPSS: Низкий
github логотип

GHSA-427h-98c5-gq24

почти 3 года назад

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-427g-prh3-hw73

больше 3 лет назад

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.

EPSS: Низкий
github логотип

GHSA-427g-2r83-3ccm

около 6 лет назад

Information disclosure through processing of external XML entities

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-427f-v2mq-364f

больше 3 лет назад

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-427f-qf2r-ffq3

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS.This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-427c-xc35-8535

больше 1 года назад

Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-427c-cc94-833h

больше 1 года назад

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4279-qvh5-v435

больше 3 лет назад

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4278-w8xg-58qx

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4278-658q-vpxq

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4278-2v5v-65r4

больше 4 лет назад

Heap buffer overflow in `RaggedBinCount`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-4277-m35q-7c9w

около 1 года назад

Salt preflight script could be attacker controlled

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4277-8779-3fvr

около 3 лет назад

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4276-cm8c-788h

6 месяцев назад

Mattermost Fails to Properly Validate Team Role Modification

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-4276-4w95-82xg

больше 3 лет назад

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-4275-m544-m6p7

около 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4274-hq9q-h55c

больше 2 лет назад

SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-427h-jcwm-rr2p

Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-427h-gjgj-xjwc

SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-427h-c47c-jgj4

OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-427h-98c5-gq24

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-427g-prh3-hw73

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-427g-2r83-3ccm

Information disclosure through processing of external XML entities

CVSS3: 4.9
0%
Низкий
около 6 лет назад
github логотип
GHSA-427f-v2mq-364f

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation) to enable the remediation.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-427f-qf2r-ffq3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS.This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-427c-xc35-8535

Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-427c-cc94-833h

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4279-qvh5-v435

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4278-w8xg-58qx

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4278-658q-vpxq

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4278-2v5v-65r4

Heap buffer overflow in `RaggedBinCount`

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4277-m35q-7c9w

Salt preflight script could be attacker controlled

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-4277-8779-3fvr

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

CVSS3: 6.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-4276-cm8c-788h

Mattermost Fails to Properly Validate Team Role Modification

CVSS3: 3.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4276-4w95-82xg

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4275-m544-m6p7

** UNSUPPORTED WHEN ASSIGNED ** A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-4274-hq9q-h55c

SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу