Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 840

Количество 301 840

github логотип

GHSA-293x-mf2v-87jf

больше 3 лет назад

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

EPSS: Низкий
github логотип

GHSA-293x-92j8-gvrh

больше 1 года назад

Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-293w-8h49-x8x8

больше 2 лет назад

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-293v-5329-36wp

больше 2 лет назад

MCMS vulnerable to arbitrary code execution via crafted thumbnail

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293v-32vx-9g86

почти 2 года назад

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293r-f52g-2w34

больше 3 лет назад

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

EPSS: Низкий
github логотип

GHSA-293r-4r95-pff2

больше 3 лет назад

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-293q-vg2m-m48p

больше 3 лет назад

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-293q-jm6v-g4pw

больше 1 года назад

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-293p-8p8x-wx39

больше 3 лет назад

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.

EPSS: Низкий
github логотип

GHSA-293m-v274-vgh4

5 месяцев назад

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-293m-rx8m-gh7h

больше 3 лет назад

MyBB 1.8.19 has XSS in the resetpassword function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-293m-43xj-42h4

больше 3 лет назад

Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.

EPSS: Низкий
github логотип

GHSA-293j-x829-fj24

больше 3 лет назад

The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293j-rh9p-w2r8

больше 3 лет назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

EPSS: Низкий
github логотип

GHSA-293j-h7h4-4rp5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-293j-3754-3xrj

больше 3 лет назад

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

EPSS: Низкий
github логотип

GHSA-293h-rg6q-5hxj

больше 3 лет назад

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

EPSS: Низкий
github логотип

GHSA-293h-f2f3-6fqq

больше 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-293h-cqj2-8x83

больше 3 лет назад

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-293x-mf2v-87jf

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293x-92j8-gvrh

Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-293w-8h49-x8x8

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-293v-5329-36wp

MCMS vulnerable to arbitrary code execution via crafted thumbnail

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-293v-32vx-9g86

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
github логотип
GHSA-293r-f52g-2w34

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293r-4r95-pff2

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293q-vg2m-m48p

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-293q-jm6v-g4pw

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-293p-8p8x-wx39

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293m-v274-vgh4

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-293m-rx8m-gh7h

MyBB 1.8.19 has XSS in the resetpassword function.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-293m-43xj-42h4

Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293j-x829-fj24

The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-293j-rh9p-w2r8

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-293j-h7h4-4rp5

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-293j-3754-3xrj

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-293h-rg6q-5hxj

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-293h-f2f3-6fqq

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-293h-cqj2-8x83

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу