Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-39rw-v9vh-37g8

почти 4 года назад

SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.

EPSS: Низкий
github логотип

GHSA-39rw-jh89-3x4q

больше 3 лет назад

An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues.

EPSS: Низкий
github логотип

GHSA-39rw-hw3x-2qp8

больше 3 лет назад

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-39rw-9mj8-p737

почти 3 года назад

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument date_from/date_to leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-223327.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-39rw-6p2v-g5r9

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-39rw-4m66-82gf

больше 3 лет назад

Magento incorrect user permissions vulnerability within the Inventory component

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-39rv-xm8f-rj7v

больше 3 лет назад

OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.

EPSS: Низкий
github логотип

GHSA-39rv-383r-32wp

почти 4 года назад

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

EPSS: Низкий
github логотип

GHSA-39rr-qw8q-xwq8

8 месяцев назад

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-39rr-hm6w-c8p2

4 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-39rr-hfc3-8pcc

больше 1 года назад

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-39rr-749r-3wmw

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-39rr-656j-h75w

больше 3 лет назад

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to read restricted memory.

EPSS: Низкий
github логотип

GHSA-39rq-cqj8-g6q7

около 4 лет назад

Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-39rq-5648-q49j

больше 3 лет назад

Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-39rp-qwx2-562v

больше 3 лет назад

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-39rp-fmqv-8wr2

около 2 лет назад

A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-39rh-q4pp-qc6p

больше 3 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-39rg-m8qv-7ff5

больше 3 лет назад

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

EPSS: Низкий
github логотип

GHSA-39rg-8h92-xq56

больше 3 лет назад

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-39rw-v9vh-37g8

SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-39rw-jh89-3x4q

An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rw-hw3x-2qp8

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-39rw-9mj8-p737

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument date_from/date_to leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-223327.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-39rw-6p2v-g5r9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-39rw-4m66-82gf

Magento incorrect user permissions vulnerability within the Inventory component

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rv-xm8f-rj7v

OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-39rv-383r-32wp

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

1%
Низкий
почти 4 года назад
github логотип
GHSA-39rr-qw8q-xwq8

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-39rr-hm6w-c8p2

Rejected reason: Not used

4 месяца назад
github логотип
GHSA-39rr-hfc3-8pcc

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-39rr-749r-3wmw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-39rr-656j-h75w

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to read restricted memory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rq-cqj8-g6q7

Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-39rq-5648-q49j

Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-39rp-qwx2-562v

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rp-fmqv-8wr2

A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-39rh-q4pp-qc6p

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rg-m8qv-7ff5

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39rg-8h92-xq56

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу