Количество 314 529
Количество 314 529
GHSA-39rw-v9vh-37g8
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.
GHSA-39rw-jh89-3x4q
An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues.
GHSA-39rw-hw3x-2qp8
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
GHSA-39rw-9mj8-p737
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument date_from/date_to leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-223327.
GHSA-39rw-6p2v-g5r9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9.
GHSA-39rw-4m66-82gf
Magento incorrect user permissions vulnerability within the Inventory component
GHSA-39rv-xm8f-rj7v
OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
GHSA-39rv-383r-32wp
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
GHSA-39rr-qw8q-xwq8
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
GHSA-39rr-hm6w-c8p2
Rejected reason: Not used
GHSA-39rr-hfc3-8pcc
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.
GHSA-39rr-749r-3wmw
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.
GHSA-39rr-656j-h75w
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to read restricted memory.
GHSA-39rq-cqj8-g6q7
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.
GHSA-39rq-5648-q49j
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.
GHSA-39rp-qwx2-562v
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
GHSA-39rp-fmqv-8wr2
A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.
GHSA-39rh-q4pp-qc6p
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
GHSA-39rg-m8qv-7ff5
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
GHSA-39rg-8h92-xq56
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-39rw-v9vh-37g8 SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-39rw-jh89-3x4q An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues. | 0% Низкий | больше 3 лет назад | ||
GHSA-39rw-hw3x-2qp8 A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-39rw-9mj8-p737 A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument date_from/date_to leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-223327. | CVSS3: 9.8 | 0% Низкий | почти 3 года назад | |
GHSA-39rw-6p2v-g5r9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows DOM-Based XSS. This issue affects Leyka: from n/a through 3.31.9. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-39rw-4m66-82gf Magento incorrect user permissions vulnerability within the Inventory component | CVSS3: 2.7 | 0% Низкий | больше 3 лет назад | |
GHSA-39rv-xm8f-rj7v OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. | 9% Низкий | больше 3 лет назад | ||
GHSA-39rv-383r-32wp Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands. | 1% Низкий | почти 4 года назад | ||
GHSA-39rr-qw8q-xwq8 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 8 месяцев назад | |
GHSA-39rr-hm6w-c8p2 Rejected reason: Not used | 4 месяца назад | |||
GHSA-39rr-hfc3-8pcc The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs. | CVSS3: 3.3 | 0% Низкий | больше 1 года назад | |
GHSA-39rr-749r-3wmw Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9. | CVSS3: 7.1 | 0% Низкий | 7 месяцев назад | |
GHSA-39rr-656j-h75w A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to read restricted memory. | 0% Низкий | больше 3 лет назад | ||
GHSA-39rq-cqj8-g6q7 Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability. | CVSS3: 9.8 | 0% Низкий | около 4 лет назад | |
GHSA-39rq-5648-q49j Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-39rp-qwx2-562v The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-39rp-fmqv-8wr2 A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability. | CVSS3: 6.3 | 0% Низкий | около 2 лет назад | |
GHSA-39rh-q4pp-qc6p SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | 0% Низкий | больше 3 лет назад | ||
GHSA-39rg-m8qv-7ff5 Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues. | 0% Низкий | больше 3 лет назад | ||
GHSA-39rg-8h92-xq56 An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу