Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4wwp-h8w8-9g3q

больше 4 лет назад

AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.

EPSS: Низкий
github логотип

GHSA-4wwm-f449-qwpq

больше 4 лет назад

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wwf-fjp5-m2vx

больше 4 лет назад

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138427.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4wwf-f7w3-94f5

8 месяцев назад

RaspAP raspap-webgui contains an OS Command Injection vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wwf-734g-mqm8

4 дня назад

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-4wwc-whcw-g74j

больше 4 лет назад

Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4wwc-hgc4-j27v

9 дней назад

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4wwc-c5pq-cg6h

около 4 лет назад

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wwc-5xpr-v7cw

больше 4 лет назад

Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-4ww9-x4qj-x6qm

около 1 года назад

A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserName value can overwrite the Structured Exception Handler (SEH), leading to arbitrary code execution when the application processes the file.

EPSS: Низкий
github логотип

GHSA-4ww9-x3qp-vcwc

около 2 лет назад

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4ww9-hf89-3gmg

больше 2 лет назад

The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4ww8-fprq-cq34

около 2 лет назад

Mattermost doesn't redact remote users' original email addresses

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4ww7-q667-367m

15 дней назад

Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4ww7-gqv6-mffc

13 дней назад

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4ww6-v8j9-4cf3

больше 4 лет назад

TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4ww6-5q5c-2gc5

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4ww6-4g26-gh9j

около 3 лет назад

A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4ww5-vxfr-977m

больше 4 лет назад

The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-4ww5-c665-7cg6

больше 4 лет назад

The Jelly Splash (aka com.wooga.jelly_splash) application 1.11.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wwp-h8w8-9g3q

AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwm-f449-qwpq

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwf-fjp5-m2vx

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138427.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwf-f7w3-94f5

RaspAP raspap-webgui contains an OS Command Injection vulnerability

CVSS3: 8.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-4wwf-734g-mqm8

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

CVSS3: 9.4
0%
Низкий
4 дня назад
github логотип
GHSA-4wwc-whcw-g74j

Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwc-hgc4-j27v

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

CVSS3: 8.1
0%
Низкий
9 дней назад
github логотип
GHSA-4wwc-c5pq-cg6h

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4wwc-5xpr-v7cw

Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww9-x4qj-x6qm

A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserName value can overwrite the Structured Exception Handler (SEH), leading to arbitrary code execution when the application processes the file.

0%
Низкий
около 1 года назад
github логотип
GHSA-4ww9-x3qp-vcwc

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

CVSS3: 9.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-4ww9-hf89-3gmg

The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4ww8-fprq-cq34

Mattermost doesn't redact remote users' original email addresses

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-4ww7-q667-367m

Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
15 дней назад
github логотип
GHSA-4ww7-gqv6-mffc

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

CVSS3: 8.3
0%
Низкий
13 дней назад
github логотип
GHSA-4ww6-v8j9-4cf3

TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww6-5q5c-2gc5

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
10%
Средний
больше 3 лет назад
github логотип
GHSA-4ww6-4g26-gh9j

A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-4ww5-vxfr-977m

The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ww5-c665-7cg6

The Jelly Splash (aka com.wooga.jelly_splash) application 1.11.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу