Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-3qxv-8pqm-xqw3

больше 4 лет назад

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker.

EPSS: Низкий
github логотип

GHSA-3qxv-6xq9-fg2r

6 месяцев назад

Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract sensitive database information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3qxr-q72q-hmwp

больше 4 лет назад

Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qxr-h63q-m7x3

больше 4 лет назад

An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qxr-cm3w-hpmq

больше 2 лет назад

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3qxr-9jgv-5jfg

больше 4 лет назад

mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.

EPSS: Низкий
github логотип

GHSA-3qxr-2r44-6w45

почти 2 года назад

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qxq-rx8j-qpmj

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.

EPSS: Низкий
github логотип

GHSA-3qxq-qwff-776p

больше 4 лет назад

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Online Help.

EPSS: Низкий
github логотип

GHSA-3qxq-5jcx-g5cg

больше 4 лет назад

SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.

EPSS: Низкий
github логотип

GHSA-3qxq-4rfh-fpmx

больше 4 лет назад

An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

EPSS: Низкий
github логотип

GHSA-3qxq-43gq-5mcw

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qxp-wv2v-jfc4

больше 2 лет назад

.NET Framework Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qxp-qjq7-w4hf

больше 5 лет назад

CHECK-fail in tf.raw_ops.EncodePng

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-3qxp-p56x-r4h3

больше 2 лет назад

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to be mapped when PV guests run, Xen and shadowed PV guests run directly the respective shadow page tables. For 64-bit PV guests this means running on the shadow of the guest root page table. In the course of dealing with shortage of memory in the shadow pool associated with a domain, shadows of page tables may be torn down. This tearing down may include the shadow root page table that the CPU in question is presently running on. While a precaution exists to supposedly prevent the tearing down of the underlying live page table, the time window covered by that precaution isn't large enough.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qxp-588w-rmqg

почти 2 года назад

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qxm-qv9f-98xq

больше 4 лет назад

SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3qxm-jwhr-5pv2

больше 4 лет назад

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qxm-8mjv-r23h

11 месяцев назад

The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via the 'woo-superb-slideshow' shortcode in all versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qxj-j9pp-55cr

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a through 1.4.3.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qxv-8pqm-xqw3

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxv-6xq9-fg2r

Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract sensitive database information.

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-3qxr-q72q-hmwp

Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxr-h63q-m7x3

An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxr-cm3w-hpmq

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qxr-9jgv-5jfg

mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxr-2r44-6w45

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3qxq-rx8j-qpmj

Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxq-qwff-776p

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Online Help.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxq-5jcx-g5cg

SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxq-4rfh-fpmx

An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxq-43gq-5mcw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3qxp-wv2v-jfc4

.NET Framework Denial of Service Vulnerability

CVSS3: 7.5
4%
Низкий
больше 2 лет назад
github логотип
GHSA-3qxp-qjq7-w4hf

CHECK-fail in tf.raw_ops.EncodePng

CVSS3: 2.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-3qxp-p56x-r4h3

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to be mapped when PV guests run, Xen and shadowed PV guests run directly the respective shadow page tables. For 64-bit PV guests this means running on the shadow of the guest root page table. In the course of dealing with shortage of memory in the shadow pool associated with a domain, shadows of page tables may be torn down. This tearing down may include the shadow root page table that the CPU in question is presently running on. While a precaution exists to supposedly prevent the tearing down of the underlying live page table, the time window covered by that precaution isn't large enough.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qxp-588w-rmqg

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qxm-qv9f-98xq

SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxm-jwhr-5pv2

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qxm-8mjv-r23h

The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via the 'woo-superb-slideshow' shortcode in all versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3qxj-j9pp-55cr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a through 1.4.3.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу