Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2hwp-jrpr-6f78

почти 4 года назад

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

EPSS: Низкий
github логотип

GHSA-2hwp-g4g7-mwwj

больше 6 лет назад

Reflected Cross-Site Scripting in jquery.terminal

EPSS: Низкий
github логотип

GHSA-2hwp-cw9h-92vp

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2hwp-94gx-j73f

12 месяцев назад

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hwp-78q9-9xwc

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Elite allows PHP Local File Inclusion. This issue affects Magazine Elite: from n/a through 1.2.4.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hwm-f3wp-3rq5

больше 1 года назад

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2hwm-966r-8hqw

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7453.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hwm-6xjf-3xmx

почти 4 года назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2hwm-56x6-pwwc

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2hwj-v42x-jfwh

больше 3 лет назад

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2hwf-vrcf-2q7m

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hwf-hm8p-fc5c

больше 1 года назад

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hwf-2vrp-g37h

больше 3 лет назад

The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hw9-m765-6g54

около 3 лет назад

CVE was unused by HPE.

EPSS: Низкий
github логотип

GHSA-2hw9-c84h-m727

больше 3 лет назад

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112856493

EPSS: Низкий
github логотип

GHSA-2hw8-qj3h-c7pq

больше 3 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

EPSS: Низкий
github логотип

GHSA-2hw7-w5mq-h4q7

больше 3 лет назад

Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hw7-mxvj-m455

около 5 лет назад

Path traversal in Node-RED-Dashboard

EPSS: Критический
github логотип

GHSA-2hw7-5qc9-q2cg

почти 4 года назад

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

EPSS: Низкий
github логотип

GHSA-2hw7-485w-9j23

почти 4 года назад

WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hwp-jrpr-6f78

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hwp-g4g7-mwwj

Reflected Cross-Site Scripting in jquery.terminal

больше 6 лет назад
github логотип
GHSA-2hwp-cw9h-92vp

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hwp-94gx-j73f

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-2hwp-78q9-9xwc

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Elite allows PHP Local File Inclusion. This issue affects Magazine Elite: from n/a through 1.2.4.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2hwm-f3wp-3rq5

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hwm-966r-8hqw

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7453.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hwm-6xjf-3xmx

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
32%
Средний
почти 4 года назад
github логотип
GHSA-2hwm-56x6-pwwc

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-2hwj-v42x-jfwh

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hwf-vrcf-2q7m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2hwf-hm8p-fc5c

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hwf-2vrp-g37h

The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw9-m765-6g54

CVE was unused by HPE.

около 3 лет назад
github логотип
GHSA-2hw9-c84h-m727

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112856493

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw8-qj3h-c7pq

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw7-w5mq-h4q7

Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw7-mxvj-m455

Path traversal in Node-RED-Dashboard

92%
Критический
около 5 лет назад
github логотип
GHSA-2hw7-5qc9-q2cg

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2hw7-485w-9j23

WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу