Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-293v-32vx-9g86

около 2 лет назад

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293r-f52g-2w34

почти 4 года назад

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

EPSS: Низкий
github логотип

GHSA-293r-4r95-pff2

почти 4 года назад

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-293q-vg2m-m48p

почти 4 года назад

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-293q-m4h6-56g9

4 месяца назад

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293q-jm6v-g4pw

почти 2 года назад

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-293p-8p8x-wx39

почти 4 года назад

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.

EPSS: Низкий
github логотип

GHSA-293m-v274-vgh4

9 месяцев назад

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-293m-rx8m-gh7h

почти 4 года назад

MyBB 1.8.19 has XSS in the resetpassword function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-293m-mfcv-f7g4

18 дней назад

File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-293m-75qg-jwrv

около 1 месяца назад

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293m-43xj-42h4

почти 4 года назад

Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.

EPSS: Низкий
github логотип

GHSA-293j-x829-fj24

почти 4 года назад

The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-293j-rh9p-w2r8

почти 4 года назад

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

EPSS: Низкий
github логотип

GHSA-293j-h7h4-4rp5

почти 4 года назад

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-293j-3754-3xrj

почти 4 года назад

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

EPSS: Низкий
github логотип

GHSA-293h-rg6q-5hxj

почти 4 года назад

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

EPSS: Низкий
github логотип

GHSA-293h-f2f3-6fqq

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-293h-cqj2-8x83

почти 4 года назад

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

EPSS: Низкий
github логотип

GHSA-293h-57f9-wc4c

почти 4 года назад

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-293v-32vx-9g86

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVSS3: 9.8
6%
Низкий
около 2 лет назад
github логотип
GHSA-293r-f52g-2w34

Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293r-4r95-pff2

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293q-vg2m-m48p

SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-293q-m4h6-56g9

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-293q-jm6v-g4pw

The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-293p-8p8x-wx39

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293m-v274-vgh4

The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-293m-rx8m-gh7h

MyBB 1.8.19 has XSS in the resetpassword function.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-293m-mfcv-f7g4

File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.

CVSS3: 4.3
0%
Низкий
18 дней назад
github логотип
GHSA-293m-75qg-jwrv

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-293m-43xj-42h4

Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293j-x829-fj24

The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-293j-rh9p-w2r8

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

4%
Низкий
почти 4 года назад
github логотип
GHSA-293j-h7h4-4rp5

Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
почти 4 года назад
github логотип
GHSA-293j-3754-3xrj

PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-293h-rg6q-5hxj

BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293h-f2f3-6fqq

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-293h-cqj2-8x83

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-293h-57f9-wc4c

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

CVSS3: 6.7
0%
Низкий
почти 4 года назад

Уязвимостей на страницу