Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-29hm-xg54-5w5x

почти 4 года назад

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29hm-w98f-87q2

почти 4 года назад

Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1, 2018) is affected by: Buffer Overflow. The impact is: remote dos. The component is: slaxlexer.c:601(funtion:slaxGetInput). The attack vector is: ./slaxproc --slax-to-xslt POC0.

EPSS: Низкий
github логотип

GHSA-29hm-v8p9-7mcg

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29hj-wgxj-rcf8

4 месяца назад

The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-29hh-v8g6-v24p

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-10191.

EPSS: Низкий
github логотип

GHSA-29hh-8jqx-6pcv

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

EPSS: Низкий
github логотип

GHSA-29hh-4255-prqq

почти 4 года назад

SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php.

EPSS: Низкий
github логотип

GHSA-29hh-2h73-48vc

около 4 лет назад

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29hg-r7c7-54fr

больше 4 лет назад

Double free in insert_many

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29hc-rp6w-74v3

почти 4 года назад

The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29h8-2658-grhq

больше 2 лет назад

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29h7-gr57-5f8r

почти 4 года назад

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-29h7-cpmq-mh8j

почти 4 года назад

A code injection vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVSS3: 7.2
EPSS: Критический
github логотип

GHSA-29h7-98xg-7fp5

почти 4 года назад

A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of improper classes. This issue affects: Tobesoft XPlatform versions prior to 9.2.2.280.

EPSS: Низкий
github логотип

GHSA-29h6-xjp2-cgj2

почти 4 года назад

A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29h6-ggvx-w3vw

почти 4 года назад

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29h6-7mm5-5wf8

около 3 лет назад

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29h6-3fpg-r7jh

почти 4 года назад

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29h5-x7wq-q49w

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

EPSS: Низкий
github логотип

GHSA-29h4-m8qc-28hv

почти 4 года назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29hm-xg54-5w5x

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29hm-w98f-87q2

Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1, 2018) is affected by: Buffer Overflow. The impact is: remote dos. The component is: slaxlexer.c:601(funtion:slaxGetInput). The attack vector is: ./slaxproc --slax-to-xslt POC0.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29hm-v8p9-7mcg

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29hj-wgxj-rcf8

The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-29hh-v8g6-v24p

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-10191.

3%
Низкий
почти 4 года назад
github логотип
GHSA-29hh-8jqx-6pcv

Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29hh-4255-prqq

SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29hh-2h73-48vc

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-29hg-r7c7-54fr

Double free in insert_many

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-29hc-rp6w-74v3

The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-29h8-2658-grhq

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29h7-gr57-5f8r

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.

CVSS3: 7.5
94%
Критический
почти 4 года назад
github логотип
GHSA-29h7-cpmq-mh8j

A code injection vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVSS3: 7.2
91%
Критический
почти 4 года назад
github логотип
GHSA-29h7-98xg-7fp5

A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of improper classes. This issue affects: Tobesoft XPlatform versions prior to 9.2.2.280.

1%
Низкий
почти 4 года назад
github логотип
GHSA-29h6-xjp2-cgj2

A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

CVSS3: 9.8
7%
Низкий
почти 4 года назад
github логотип
GHSA-29h6-ggvx-w3vw

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29h6-7mm5-5wf8

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-29h6-3fpg-r7jh

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29h5-x7wq-q49w

Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

0%
Низкий
почти 4 года назад
github логотип
GHSA-29h4-m8qc-28hv

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.

CVSS3: 8.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу