Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g4p-5fvp-37cw

больше 4 лет назад

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

EPSS: Низкий
github логотип

GHSA-4g4p-42wc-9f3m

больше 4 лет назад

Git LFS can execute a Git binary from the current directory

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-4g4m-cxv2-r9h9

больше 4 лет назад

Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g4m-73g5-7x72

около 4 лет назад

A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g4m-5m32-4h55

больше 4 лет назад

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4g4m-4574-88xm

больше 4 лет назад

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later

EPSS: Низкий
github логотип

GHSA-4g4m-32hr-qwg6

4 месяца назад

Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g4j-v56v-2w79

7 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-4g4j-8g2w-gqh9

2 месяца назад

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g4j-672p-6638

больше 2 лет назад

Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g4j-2jp8-92qm

больше 4 лет назад

SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.

EPSS: Низкий
github логотип

GHSA-4g4h-9c64-2wvp

больше 4 лет назад

Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.

EPSS: Низкий
github логотип

GHSA-4g4h-5x37-mv6j

больше 1 года назад

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4g4g-xgc9-whvx

больше 4 лет назад

Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

EPSS: Низкий
github логотип

GHSA-4g4g-rjvv-wjx5

больше 4 лет назад

MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

EPSS: Низкий
github логотип

GHSA-4g4g-rcx9-4779

больше 4 лет назад

ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g4g-fqw4-prp2

больше 1 года назад

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g4f-rmrm-vw9w

больше 4 лет назад

Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g4f-j7gv-ph46

больше 1 года назад

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g4c-mfqg-pj8r

6 месяцев назад

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g4p-5fvp-37cw

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4p-42wc-9f3m

Git LFS can execute a Git binary from the current directory

CVSS3: 9.8
83%
Высокий
больше 4 лет назад
github логотип
GHSA-4g4m-cxv2-r9h9

Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4m-73g5-7x72

A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4g4m-5m32-4h55

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4m-4574-88xm

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4m-32hr-qwg6

Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4g4j-v56v-2w79

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
12%
Средний
7 месяцев назад
github логотип
GHSA-4g4j-8g2w-gqh9

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4g4j-672p-6638

Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4g4j-2jp8-92qm

SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4h-9c64-2wvp

Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4h-5x37-mv6j

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g4g-xgc9-whvx

Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4g-rjvv-wjx5

MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4g-rcx9-4779

ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4g-fqw4-prp2

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions...

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-4g4f-rmrm-vw9w

Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4f-j7gv-ph46

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g4c-mfqg-pj8r

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

0%
Низкий
6 месяцев назад

Уязвимостей на страницу