Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-39cr-wrpx-ww2j

около 1 года назад

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

EPSS: Низкий
github логотип

GHSA-39cr-m23q-9x5f

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing Statistics: from n/a through 4.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-39cr-fcrw-jv5q

почти 4 года назад

SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.

EPSS: Низкий
github логотип

GHSA-39cr-9663-62x5

больше 3 лет назад

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.

EPSS: Низкий
github логотип

GHSA-39cq-84vm-mrq4

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-39cp-8qfj-8cjm

почти 2 года назад

An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-39cp-3xcg-82ch

больше 1 года назад

A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of the component Account Information Page. The manipulation of the argument userid leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-39cj-q7jm-v7pc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-39cj-hgvp-8pvv

больше 3 лет назад

Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-39cj-7596-887h

больше 3 лет назад

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-39cj-5fqw-pw57

больше 3 лет назад

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0097.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-39cj-3mcf-vq77

больше 3 лет назад

An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-39ch-rg26-gmq5

больше 3 лет назад

Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

CVSS3: 6.9
EPSS: Средний
github логотип

GHSA-39ch-q5j8-9rjh

почти 4 года назад

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-39cf-qv36-cvx3

больше 3 лет назад

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-39cf-mg8f-v5hq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2006-5074. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-39cf-f784-9gfv

10 месяцев назад

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-39c9-vp8c-xpgv

почти 4 года назад

SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie.

EPSS: Низкий
github логотип

GHSA-39c9-vmq6-wcfw

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4.

EPSS: Низкий
github логотип

GHSA-39c9-283p-pj5f

больше 3 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-39cr-wrpx-ww2j

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

0%
Низкий
около 1 года назад
github логотип
GHSA-39cr-m23q-9x5f

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing Statistics: from n/a through 4.5.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-39cr-fcrw-jv5q

SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.

0%
Низкий
почти 4 года назад
github логотип
GHSA-39cr-9663-62x5

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39cq-84vm-mrq4

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-39cp-8qfj-8cjm

An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-39cp-3xcg-82ch

A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of the component Account Information Page. The manipulation of the argument userid leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-39cj-q7jm-v7pc

Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-39cj-hgvp-8pvv

Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-39cj-7596-887h

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

CVSS3: 9.8
16%
Средний
больше 3 лет назад
github логотип
GHSA-39cj-5fqw-pw57

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0097.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-39cj-3mcf-vq77

An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-39ch-rg26-gmq5

Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies

CVSS3: 6.9
24%
Средний
больше 3 лет назад
github логотип
GHSA-39ch-q5j8-9rjh

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS3: 9.8
39%
Средний
почти 4 года назад
github логотип
GHSA-39cf-qv36-cvx3

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-39cf-mg8f-v5hq

Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2006-5074. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-39cf-f784-9gfv

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-39c9-vp8c-xpgv

SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie.

0%
Низкий
почти 4 года назад
github логотип
GHSA-39c9-vmq6-wcfw

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4.

0%
Низкий
9 месяцев назад
github логотип
GHSA-39c9-283p-pj5f

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу