Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w3v-j6fg-rqmc

больше 4 лет назад

Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote attackers to write arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4w3v-83v8-mg94

больше 4 лет назад

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4w3v-49qq-fg93

около 1 года назад

Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the saveNICParamsToFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to write files in the context of SYSTEM. Was ZDI-CAN-24921.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4w3r-jhc2-fjv6

больше 4 лет назад

PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.

EPSS: Низкий
github логотип

GHSA-4w3r-95jc-3289

10 месяцев назад

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4w3q-qpfq-v992

2 месяца назад

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w3q-jm8g-g5x4

больше 4 лет назад

In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w3q-gj3x-9575

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Prevent release of buffer in I/O When a task waiting for completion of a Store Data operation is interrupted, an attempt is made to halt this operation. If this attempt fails due to a hardware or firmware problem, there is a chance that the SCLP facility might store data into buffers referenced by the original operation at a later time. Handle this situation by not releasing the referenced data buffers if the halt attempt fails. For current use cases, this might result in a leak of few pages of memory in case of a rare hardware/firmware malfunction.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4w3q-g484-rj57

2 месяца назад

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4w3q-g25g-r489

15 дней назад

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w3m-xm3w-43g9

больше 4 лет назад

In Modicon Quantum all firmware versions, CWE-264: Permissions, Privileges, and Access Control vulnerabilities could cause a denial of service or unauthorized modifications of the PLC configuration when using Ethernet/IP protocol.

EPSS: Низкий
github логотип

GHSA-4w3m-mc38-3x42

больше 4 лет назад

The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.

EPSS: Средний
github логотип

GHSA-4w3j-cmwq-6m3q

2 дня назад

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4w3j-8hm6-fjqq

больше 4 лет назад

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4w3j-8fcj-qpw3

больше 4 лет назад

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.

EPSS: Низкий
github логотип

GHSA-4w3j-4m96-c92x

больше 2 лет назад

Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4w3h-xrfh-9v5v

больше 4 лет назад

Possible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-4w3h-ggjg-2hvj

почти 5 лет назад

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4w3g-mpj2-j247

больше 4 лет назад

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4w3g-775c-9368

19 дней назад

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w3v-j6fg-rqmc

Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote attackers to write arbitrary files via unspecified vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3v-83v8-mg94

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVSS3: 9.8
99%
Критический
больше 4 лет назад
github логотип
GHSA-4w3v-49qq-fg93

Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the saveNICParamsToFile method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to write files in the context of SYSTEM. Was ZDI-CAN-24921.

CVSS3: 8.2
1%
Низкий
около 1 года назад
github логотип
GHSA-4w3r-jhc2-fjv6

PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3r-95jc-3289

Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-4w3q-qpfq-v992

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-4w3q-jm8g-g5x4

In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3q-gj3x-9575

In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Prevent release of buffer in I/O When a task waiting for completion of a Store Data operation is interrupted, an attempt is made to halt this operation. If this attempt fails due to a hardware or firmware problem, there is a chance that the SCLP facility might store data into buffers referenced by the original operation at a later time. Handle this situation by not releasing the referenced data buffers if the halt attempt fails. For current use cases, this might result in a leak of few pages of memory in case of a rare hardware/firmware malfunction.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4w3q-g484-rj57

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site...

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4w3q-g25g-r489

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
15 дней назад
github логотип
GHSA-4w3m-xm3w-43g9

In Modicon Quantum all firmware versions, CWE-264: Permissions, Privileges, and Access Control vulnerabilities could cause a denial of service or unauthorized modifications of the PLC configuration when using Ethernet/IP protocol.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3m-mc38-3x42

The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.

12%
Средний
больше 4 лет назад
github логотип
GHSA-4w3j-cmwq-6m3q

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 9.1
2%
Низкий
2 дня назад
github логотип
GHSA-4w3j-8hm6-fjqq

IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3j-8fcj-qpw3

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3j-4m96-c92x

Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4w3h-xrfh-9v5v

Possible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3h-ggjg-2hvj

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4w3g-mpj2-j247

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w3g-775c-9368

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

CVSS3: 5.4
0%
Низкий
19 дней назад

Уязвимостей на страницу